DNS Cache Poisoning Vulnerability in Knot Resolver from CZ.NIC
CVE-2022-32983

5.3MEDIUM

Key Information:

Vendor

Nic

Vendor
CVE Published:
20 June 2022

What is CVE-2022-32983?

A vulnerability in Knot Resolver, specifically in versions up to 5.5.1, allows for potential DNS cache poisoning. This occurs when attempts are made to limit forwarding actions via filters, which may lead to the manipulation of DNS responses. This presents a significant risk as attackers can exploit this vulnerability to interfere with DNS queries, potentially redirecting users to malicious sites. Organizations using this software are advised to review their configurations and consider applying mitigations as recommended by the vendor.

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.