#VU66540 Input validation error in Domain Name Relay Daemon - CVE-2022-33993

 

#VU66540 Input validation error in Domain Name Relay Daemon - CVE-2022-33993

Published: August 16, 2022


Vulnerability identifier: #VU66540
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-33993
CWE-ID: CWE-20
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
Domain Name Relay Daemon
Software vendor:
DNRD

Description

The vulnerability allows a remote attacker to perform DNS cache poisoning attacks.

The vulnerability exists due to insufficient validation of special domain name characters. A remote attacker can send specially crafted input to the server and perform DNS cache poisoning attacks.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links