CVE-2023-50868
HIGHISC Bind < 9.16.48 - Denial of Service
Title source: ruleDescription
The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.
Exploits (1)
nomisec
WORKING POC
6 stars
by Goethe-Universitat-Cybersecurity · poc
https://github.com/Goethe-Universitat-Cybersecurity/NSEC3-Encloser-Attack
References (29)
... and 9 more
Scores
CVSS v3
7.5
EPSS
0.1180
EPSS Percentile
93.6%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Classification
CWE
CWE-400
Status
published
Affected Products (16)
isc/bind
< 9.16.48
isc/bind
< 9.16.48
isc/bind
< 9.18.24
fedoraproject/fedora
fedoraproject/fedora
debian/debian_linux
debian/debian_linux
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
redhat/enterprise_linux
powerdns/recursor
< 4.8.5
netapp/bootstrap_os
netapp/active_iq_unified_manager
... and 1 more
Timeline
Published
Feb 14, 2024
Tracked Since
Feb 18, 2026