HIGH · 7.5

CVE-2023-50387

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka...

Vulnerability Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

CVSS Score

7.5

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
RedhatEnterprise Linux6.0
MicrosoftWindows Server 2008r2
MicrosoftWindows Server 2012-
MicrosoftWindows Server 2016-
MicrosoftWindows Server 2019-
MicrosoftWindows Server 2022-
MicrosoftWindows Server 2022 23H2-
FedoraprojectFedora39
ThekelleysDnsmasq< 2.90
NicKnot Resolver< 5.71
PowerdnsRecursor>= 4.8.0, < 4.8.6
IscBind>= 9.0.0, <= 9.16.46
NlnetlabsUnbound< 1.19.1

Related Weaknesses (CWE)

References

FAQ

What is CVE-2023-50387?

CVE-2023-50387 is a vulnerability with a CVSS score of 7.5 (HIGH). Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka...

How severe is CVE-2023-50387?

CVE-2023-50387 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2023-50387?

Check the references section above for vendor advisories and patch information. Affected products include: Redhat Enterprise Linux, Microsoft Windows Server 2008, Microsoft Windows Server 2012, Microsoft Windows Server 2016, Microsoft Windows Server 2019.