Impact
The vulnerability is a denial of service in the PRSD detection module of PowerDNS DNSdist. The flaw enables an attacker to send crafted inputs that lead to the crash or resource exhaustion of the DNSdist server, effectively interrupting DNS services for users connected to that instance. The weakness corresponds to CWE-116, which involves incorrect handling of string parsing leading to service disruption.
Affected Systems
The affected product is PowerDNS DNSdist. No specific version information is provided, so all installations of DNSdist may be impacted until a patch is released by the vendor.
Risk and Exploitability
The CVSS score of 3.7 classifies the vulnerability as low severity, and the EPSS score is not available, indicating a lack of publicly known exploitation. The issue is not listed in the CISA KEV catalog. The likely attack vector is a remote network request; this inference is based on the nature of DNS services, though the official description does not specify it. Exploitation would require an attacker to craft and send malformed PRSD detection queries that trigger the flaw, which may lead to a crash or denial of service for users of the affected DNSdist instance.
OpenCVE Enrichment