Impact
The flaw arises when an authoritative server responds slowly and the cached records expire during that time. In this situation the software does not enforce TTL limits because it lacks fresh data, allowing almost expired records to be used for authentication. This behavior can be exploited to poison the recursor’s cache with incorrect name server information, leading to persistent redirection of domain lookups to malicious endpoints.
Affected Systems
The vulnerability affects the PowerDNS Recursor product. No specific version numbers are listed, so any installation of PowerDNS Recursor that has not applied a vendor update may be impacted.
Risk and Exploitability
With a CVSS score of 3.7 the severity is considered low, and the EPSS score of less than 1% indicates a very small probability of exploitation in the wild. The vulnerability is not included in the CISA KEV catalog. The attack requires an attacker to induce a slow response from an authoritative DNS server and wait for cached records to expire, after which stale information can be written into the cache. While the exploit path is non‑trivial, the persistence of the poisoned cache makes it a concern in environments that rely heavily on cached DNS data.
OpenCVE Enrichment