Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-xxc5-5ggq-v5qj

Опубликовано: 07 апр. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.1

Описание

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses and poison the DNS cache, potentially redirecting victims to attacker-controlled destinations.

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses and poison the DNS cache, potentially redirecting victims to attacker-controlled destinations.

EPSS

Процентиль: 37%
0.00451
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 9.1
nvd
4 месяца назад

Dual DHCP DNS Server 8.01 improperly accepts and caches UDP DNS responses without validating that the response originates from a legitimate configured upstream DNS server. The implementation matches responses primarily by TXID and inserts results into the cache, enabling a remote attacker to inject forged responses and poison the DNS cache, potentially redirecting victims to attacker-controlled destinations.

EPSS

Процентиль: 37%
0.00451
Низкий

9.1 Critical

CVSS3

Дефекты

CWE-94