Configuration Injection in Unbound Due to Community Script Vulnerability
CVE-2019-25031

5.9MEDIUM

Key Information:

Vendor

Nlnetlabs

Status
Vendor
CVE Published:
27 April 2021

What is CVE-2019-25031?

A configuration injection vulnerability exists in the community-contributed script 'create_unbound_ad_servers.sh' in Unbound, prior to version 1.9.5. This vulnerability can be exploited through a successful man-in-the-middle attack on a cleartext HTTP session, potentially allowing an attacker to alter configurations unknowingly. It's important to note that the script is not part of the official Unbound installation and thus, the vendor does not classify this as a vulnerability within Unbound software itself.

References

CVSS V3.1

Score:
5.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.