CVE-2020-5591

HIGH

XACK DNS < 1.7.18 - Denial of Service via Uncontrolled Recursion

Title source: llm
STIX 2.1

Description

XACK DNS 1.11.0 to 1.11.4, 1.10.0 to 1.10.8, 1.8.0 to 1.8.23, 1.7.0 to 1.7.18, and versions before 1.7.0 allow remote attackers to cause a denial of service condition resulting in degradation of the recursive resolver's performance or compromising the recursive resolver as a reflector in a reflection attack.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://xack.co.jp/info/?ID=622
Mitigation, Third Party Advisory, VDB Entry x_refsource_misc
https://jvn.jp/en/jp/JVN40208370/index.html

Scores

CVSS v3 7.5
EPSS 0.0164
EPSS Percentile 73.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-674
Status published
Products (1)
xack/xack_dns < 1.7.18
Published Jun 05, 2020
Tracked Since Feb 18, 2026