ZeroHour

CVE-2019-3807

CVSS 3.0
9.8 critical
EPSS
<1%p29
Published
()
Modified
Description

An issue has been found in PowerDNS Recursor versions 4.1.x before 4.1.9 where records in the answer section of responses received from authoritative servers with the AA flag not set were not properly validated, allowing an attacker to bypass DNSSEC validation.

Vendors
powerdns
Products
recursor
Weakness
CWE-345, CWE-295
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.