PowerDNS Vulnerabilities and Affected Products
Vulnerabilities associated with pdns.
Products
Clear product- Recursor30 vulnerabilities
- DNSdist28 vulnerabilities
- Authoritative12 vulnerabilities
- PowerDNS Recursor3 vulnerabilities
- pdns2 vulnerabilities
- PowerDNS2 vulnerabilities
- authoritative_server1 vulnerability
- pdns-recursor1 vulnerability
- PowerDNS Authoritative1 vulnerability
- PowerDNS Authoritative Server1 vulnerability
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2019-10163MEDIUM | A Vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.9, 4.0.8 allowing a remote, authorized master server to cause a high CPU load or even prevent any further updates to any slave zone by sending a large number of NOTIFY messages. Note that only servers configured as slaves are affected by this issue. CWE-770Jul 30, 2019 | CVSS4.3v3.1 | EPSS1% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2019-10162HIGH | A vulnerability has been found in PowerDNS Authoritative Server before versions 4.1.10, 4.0.8 allowing an authorized user to cause the server to exit by inserting a crafted record in a MASTER type zone under their control. The issue is due to the fact that the Authoritative Server will exit when it runs into a parsing error while looking up the NS/A/AAAA records it is about to use for an outgoing notify. CWE-400Jul 30, 2019 | CVSS7.5v3.1 | EPSS1.69% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |