Denial of Service Vulnerability in PowerDNS Authoritative Server
CVE-2016-5427
7.5HIGH
Summary
The PowerDNS Authoritative Server, prior to version 3.4.10, is susceptible to a denial of service condition due to improper handling of a dot (.) character within DNS labels. This vulnerability enables remote attackers to create specially crafted DNS queries that can lead to increased backend CPU consumption, ultimately affecting the server's performance and availability.
References
EPSS Score
32% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved