PowerDNS Vulnerabilities and Affected Products
Vulnerabilities associated with PowerDNS.
Products
Clear product- Recursor30 vulnerabilities
- DNSdist28 vulnerabilities
- Authoritative12 vulnerabilities
- PowerDNS Recursor3 vulnerabilities
- pdns2 vulnerabilities
- PowerDNS2 vulnerabilities
- authoritative_server1 vulnerability
- pdns-recursor1 vulnerability
- PowerDNS Authoritative1 vulnerability
- PowerDNS Authoritative Server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2024-25583HIGH | Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configuredA crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected. CWE-20Apr 25, 2024 | CVSS7.5v3.1 | EPSS0.832% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2017-15090MEDIUM | An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records. CWE-347Jan 23, 2018 | CVSS5.9v3.0 | EPSS0.611% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |