CVE 7.5 HIGH

A Recursor configured to send out ECS enabled queries can be sensitive to spoofing attempts_CVE-2025-30192

7.5 / 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Description

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries.

The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers.

The most strict mitigation done when the new setting outgoing.edns_subnet_harden (old style name edns-subnet-harden) is enabled.

Basic Information

ID CVE-2025-30192
Source OX
Published Jul 21, 2025 at 12:49
Modified Jul 21, 2025 at 13:05

Affected Product

Vendor PowerDNS
Product Recursor
Version 5.0.12

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.