Vulnerabilities
Vulnerable Software
Nlnetlabs:  >> Nsd  >> 4.1.18  Security Vulnerabilities
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes in over TLS over the regular tls-port (and not the tls-auth-port) or over over TCP over the regular port, when the other conditions of the provide-xfr rule match.
CVSS Score
8.2
EPSS Score
0.001
Published
2026-06-25


Contact Us

Shodan ® - All rights reserved