← Back

CVE-2023-50868

nvd nist
Published: Feb 14, 2024Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an algorithm must perform thousands of iterations of a hash function in certain situations.

Affected (20)

Show all products
3 products
Active Iq Unified Manager
Bootstrap Os
1 product
Recursor
1 product
Enterprise Linux
1 product
Debian Linux
1 product
Fedora
1 product
Bind
Configuration A
1 vulnerable · 5 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
H300s
All versions
Netapp
H410c
All versions
Netapp
H410s
All versions
Netapp
H500s
All versions
Netapp
H700s
All versions
Configuration B
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Configuration C
1 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
All versions
Running on/withPlatform Versions
Netapp
Hci Compute Node
All versions
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Powerdns
Before 4.8.5
From 4.9.0 to 4.9.3
From 5.0.0 to 5.0.2
Configuration E
5 vulnerable
Vulnerable SoftwareAffected Versions
Redhat
Version 6.0
Version 7.0
Version 8.0
Version 8.2
Version 8.4
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Debian
Version 10.0
Version 11.0
Configuration G
2 vulnerable
Vulnerable SoftwareAffected Versions
Fedoraproject
Version 38
Version 39
Configuration H
5 vulnerable
Vulnerable SoftwareAffected Versions
Isc
From 9.0.0 to 9.16.48
From 9.18.0 to 9.18.24
From 9.19.0 to 9.19.21
From 9.9.3 to 9.16.48
From 9.18.11 to 9.18.24

References (53)

Source: cve@mitre.org
Issue TrackingMailing List
Source: cve@mitre.org
Issue TrackingMailing List
Source: cve@mitre.org
Vendor Advisory
Source: cve@mitre.org
Issue Tracking
Source: cve@mitre.org
Technical Description
Source: cve@mitre.org
Third Party Advisory
Source: cve@mitre.org
Mailing ListVendor Advisory
Source: cve@mitre.org
Mailing ListVendor Advisory
Source: cve@mitre.org
ExploitMitigationPress/Media Coverage
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingMailing List
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue Tracking
Source: af854a3a-2127-422b-91ae-364da2661108
Technical Description
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListRelease Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Release Notes
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMitigationPress/Media Coverage

Timeline

No history available yet.