Vulnerabilities
Vulnerable Software
Powerdns:  >> Recursor  >> 4.7.4  Security Vulnerabilities
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
CVSS Score
7.5
EPSS Score
0.138
Published
2024-02-14
Denial of service vulnerability in PowerDNS Recursor allows authoritative servers to be marked unavailable.This issue affects Recursor: through 4.6.5, through 4.7.4 , through 4.8.3.
CVSS Score
3.4
EPSS Score
0.0
Published
2023-04-04


Contact Us

Shodan ® - All rights reserved