Impact
In Unbound 1.6.2 through 1.25.1, the respip module can rewrite DNS responses that are marked as BOGUS by the validator once a response‑ip rule or RPZ rule is applied. The rewriting logic ignores the security status and forces such responses to a pre‑configured IP address, assigning them an INSECURE security level. This allows an attacker to spoof a DNSSEC‑protected name that falls within the rewritten subnet and have clients receive a fake answer that resolves to the operator’s IP, effectively bypassing DNSSEC protections.
Affected Systems
NLnet Labs Unbound versions 1.6.2 to 1.25.1 when the respip module is used in front of the validator and when a response‑ip redirect rule or an RPZ file with an RPZ‑IP trigger is configured. These products are vulnerable when running those specific releases.
Risk and Exploitability
The CVSS score is 6.3, indicating moderate severity. EPSS score is <1%, suggesting a very low but non‑zero exploitation probability, and the vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the attack can be carried out remotely by an entity that can inject DNS traffic—such as a compromised upstream server or a data center that can send spoofed responses—targeting names that match the configured rewrite rules. Once triggered, the client receives an INSECURE NOERROR answer pointing to an attacker‑controlled IP, leading to data leakage or session hijacking. Because no additional authentication is required, the risk of exploitation is significant in environments that expose Unbound widely.
OpenCVE Enrichment