CVE-2020-10995
Last modified
CVE-2020-10995 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. EPSS estimates a 4.37% chance of exploitation in the next 30 days.
Description
PowerDNS Recursor from 4.1.0 up to and including 4.3.0 does not sufficiently defend against amplification attacks. An issue in the DNS protocol has been found that allow malicious parties to use recursive DNS services to attack third party authoritative name servers. The attack uses a crafted reply by an authoritative name server to amplify the resulting traffic between the recursive and other authoritative name servers. Both types of service can suffer degraded performance as an effect. This is triggered by random subdomains in the NSDNAME in NS records. PowerDNS Recursor 4.1.16, 4.2.2 and 4.3.1 contain a mitigation to limit the impact of this DNS protocol issue.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Powerdns | Recursor | >= 4.1.0, <= 4.3.0 | — |
| Fedoraproject | Fedora | 31 | — |
| Fedoraproject | Fedora | 32 | — |
| Debian | Debian Linux | 10.0 | — |
| Opensuse | Backports Sle | 15.0 | Sp1 |
| Opensuse | Leap | 15.1 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00052.htmlMailing List, Third Party Advisory
- http://www.nxnsattack.comTechnical Description, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4691Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-05/msg00052.htmlMailing List, Third Party Advisory
- http://www.nxnsattack.comTechnical Description, Third Party Advisory
- https://www.debian.org/security/2020/dsa-4691Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-10995?
How severe is CVE-2020-10995?
How do I fix CVE-2020-10995?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-1099A cross-site-scripting (XSS) vulnerability exists when Micro…5.4
- CVE-2020-10990An XXE issue exists in Accenture Mercury before 1.12.28 beca…9.8
- CVE-2020-10991Mulesoft APIkit through 1.3.0 allows XXE because of validati…9.8
- CVE-2020-10992Azkaban through 3.84.0 allows XXE, related to validator/XmlV…9.8
- CVE-2020-10993Osmand through 2.0.0 allow XXE because of binary/BinaryMapIn…9.1
- CVE-2020-10994In libImaging/Jpeg2KDecode.c in Pillow before 7.1.0, there a…5.5
- CVE-2020-10996An issue was discovered in Percona XtraDB Cluster before 5.7…8.1
- CVE-2020-10997Percona XtraBackup before 2.4.20 unintentionally writes the …6.5
- CVE-2020-1100A cross-site-scripting (XSS) vulnerability exists when Micro…5.4
- CVE-2020-11000GreenBrowser before version 1.2 has a vulnerability where ap…6.5
- CVE-2020-11001In Wagtail before versions 2.8.1 and 2.7.2, a cross-site scr…6.8
- CVE-2020-11002dropwizard-validation before versions 2.0.3 and 1.3.21 has a…8.8
Are you affected by CVE-2020-10995?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
