Zero-friction vulnerability management platform

Mageni eases for you the vulnerability scanning, assessment, and management process. It is free and open-source.

Install Now

Available for macOS, Windows, and Linux

App screenshot

PowerDNS Authoritative Server DoS Vulnerability

Information

Severity

Severity

Medium

Family

Family

Denial of Service

CVSSv2 Base

CVSSv2 Base

5.5

CVSSv2 Vector

CVSSv2 Vector

AV:N/AC:L/Au:S/C:N/I:P/A:P

Solution Type

Solution Type

Vendor Patch

Created

Created

4 years ago

Modified

Modified

3 years ago

Summary

PowerDNS Authoritative Server is prone to a denial of service vulnerability.

Insight

Insight

An issue has been found in the API component of PowerDNS Authoritative, where some operations that have an impact on the state of the server are still allowed even though the API has been configured as read-only via the api-readonly keyword. This missing check allows an attacker with valid API credentials could flush the cache, trigger a zone transfer or send a NOTIFY.

Affected Software

Affected Software

PowerDNS Authoritative up to and including 4.0.4, 3.4.11.

Detection Method

Detection Method

Checks if a vulnerable version is present on the target host.

Solution

Solution

Upgrade to version 4.0.5 or later.

Common Vulnerabilities and Exposures (CVE)