SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2023-50387

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue.

HIGH 7.5EPSS 100.0%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 100.0%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.

Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

CVSS 3.1
7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS
100.00% probability · 100th percentile
CISA KEV
Not listed
Weakness
CWE-770
Affected
redhat/enterprise linux · microsoft/windows server 2008 · microsoft/windows server 2012 · microsoft/windows server 2016 · microsoft/windows server 2019 · microsoft/windows server 2022 · microsoft/windows server 2022 23h2 · fedoraproject/fedora · thekelleys/dnsmasq · nic/knot resolver · powerdns/recursor · isc/bind · nlnetlabs/unbound
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.