gist.github.com
https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3 CVE-2023-28456
HIGH
Record summary
CVE-2023-28456 has a selected CVSS score of 7.5 (high).
Description
An issue was discovered in Technitium through 11.0.2. It enables attackers to launch amplification attacks (3 times more than other "golden model" software like BIND) and cause potential DoS.
Description source: CVE List
Exploitation context
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 18, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
dns_serverBrowse technitium / dns_serverDefault status: unknown | CVE List | Through 11.0.2 | affected |
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-28456 technitium.com
https://technitium.com/dns