PT-2022-21954 · Dnrd · Dnrd
Haya Shulman
+2
·
Published
2022-08-15
·
Updated
2022-08-18
·
CVE-2022-33992
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
DNRD (aka Domain Name Relay Daemon) version 2.20.3
Description
The issue concerns the forwarding and caching of DNS queries with the CD bit set to 1, which results in the disabling of DNSSEC protection provided by upstream resolvers. This affects the security of DNS queries.
Recommendations
For DNRD version 2.20.3, consider disabling the caching of DNS queries with the CD bit set to 1 until a patch is available. Restrict access to the DNS query forwarding feature to minimize the risk of exploitation. Avoid using the CD bit in DNS queries until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dnrd