CVE-2023-28451
HIGHTechnitium DNS Server 11.0.2 - Denial of Service via BadDNS Response Forgery
Title source: llmDescription
An issue was discovered in Technitium 11.0.2. There is a vulnerability (called BadDNS) in DNS resolving software, which triggers a resolver to ignore valid responses, thus causing DoS (denial of service) for normal resolution. The effects of an exploit would be widespread and highly impactful, because the attacker could just forge a response targeting the source port of a vulnerable resolver without the need to guess the correct TXID.
References (2)
Core 2
Core References
Product
https://technitium.com/dns/
Scores
CVSS v3
7.5
EPSS
0.0051
EPSS Percentile
39.3%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-400
Status
published
Products (1)
technitium/dnsserver
11.0.2
Published
Sep 18, 2024
Tracked Since
Feb 18, 2026