Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2022-3204— NRDelegation Attack

Quick assessment

Affected
NLnet Labs Unbound
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

NLnet Labs Unbound是NLnet Labs公司的一款开源DNS服务器。 NLnet Labs Unbound 1.16.3 之前版本存在安全漏洞,该漏洞源于Unbound不会受到高CPU使用率的影响,但仍需要资源来解决恶意委托,会不断尝试解析记录,直到达到硬限制。根据攻击和回复的性质,可能会达到不同的限制。

AI Predicted 7.5 Difficulty: Moderate EPSS 1.64% · P76
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2022-3204

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
NRDelegation Attack
Source: CVE Program / CVE List V5
Vulnerability Description
A vulnerability named 'Non-Responsive Delegation Attack' (NRDelegation Attack) has been discovered in various DNS resolving software. The NRDelegation Attack works by having a malicious delegation with a considerable number of non responsive nameservers. The attack starts by querying a resolver for a record that relies on those unresponsive nameservers. The attack can cause a resolver to spend a lot of time/resources resolving records under a malicious delegation point where a considerable number of unresponsive NS records reside. It can trigger high CPU usage in some resolver implementations that continually look in the cache for resolved NS records in that delegation. This can lead to degraded performance and eventually denial of service in orchestrated attacks. Unbound does not suffer from high CPU usage, but resources are still needed for resolving the malicious delegation. Unbound will keep trying to resolve the record until hard limits are reached. Based on the nature of the attack and the replies, different limits could be reached. From version 1.16.3 on, Unbound introduces fixes for better performance when under load, by cutting opportunistic queries for nameserver discovery and DNSKEY prefetching and limiting the number of times a delegation point can issue a cache lookup for missing records.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5
Vulnerability Title
NLnet Labs Unbound 资源管理错误漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
NLnet Labs Unbound是NLnet Labs公司的一款开源DNS服务器。 NLnet Labs Unbound 1.16.3 之前版本存在安全漏洞,该漏洞源于Unbound不会受到高CPU使用率的影响,但仍需要资源来解决恶意委托,会不断尝试解析记录,直到达到硬限制。根据攻击和回复的性质,可能会达到不同的限制。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
NLnet Labs Unbound unspecified ~ 1.16.2 -

II. Public POCs for CVE-2022-3204

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2022-3204

请登录查看更多情报信息。

Vendor Advisories for CVE-2022-3204 (1)

Mailing List Discussions for CVE-2022-3204 (4)

Other References for CVE-2022-3204 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2022-3204

No comments yet


Leave a comment