Showing 2 vulnerabilities on this page for PowerDNS

Signals CISA KEV Ransomware Nuclei
PowerDNS vulnerability results
VulnerabilityTitle and contextCVSSEPSSPoCsSignalsSTIX action

Crafted responses can lead to a denial of service in Recursor if recursive forwarding is configured

A crafted response from an upstream server the recursor has been configured to forward-recurse to can cause a Denial of Service in the Recursor. The default configuration of the Recursor does not use recursive forwarding and is not affected.

CWE-20Apr 25, 2024
CVSS7.5v3.1EPSS0.832%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

CWE-347Jan 23, 2018
CVSS5.9v3.0EPSS0.611%PoCs0SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templatesSTIX