CVE-2017-15093
Last modified
CVE-2017-15093 is a vulnerability of currently unknown severity. When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.. EPSS estimates a 0.84% chance of exploitation in the next 30 days.
Description
When api-config-dir is set to a non-empty value, which is not the case by default, the API in PowerDNS Recursor 4.x up to and including 4.0.6 and 3.x up to and including 3.7.4 allows an authorized user to update the Recursor's ACL by adding and removing netmasks, and to configure forward zones. It was discovered that the new netmask and IP addresses of forwarded zones were not sufficiently validated, allowing an authenticated user to inject new configuration directives into the Recursor's configuration.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Powerdns | Recursor | >= 3.0, <= 3.7.4 |
| Powerdns | Recursor | >= 4.0.0, <= 4.0.6 |
References
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-06.htmlMitigation, Patch, Vendor Advisory
- http://www.securityfocus.com/bid/101982Third Party Advisory, VDB Entry
- https://doc.powerdns.com/recursor/security-advisories/powerdns-advisory-2017-06.htmlMitigation, Patch, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-15093?
How severe is CVE-2017-15093?
How do I fix CVE-2017-15093?
Are you affected by CVE-2017-15093?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
