Impact
The flaw resides in PowerDNS Recursor’s handling of DNSSEC NSEC/NSEC3 wildcard expansion proofs. When a wildcard answer is a CNAME or DNAME record, the recursor inappropriately accepts the proof without verifying the accompanying digital signature. This deficiency permits an attacker to inject fabricated DNS records that appear legitimate to clients, undermining the authenticity guarantees that DNSSEC is designed to provide.
Affected Systems
All releases of PowerDNS Recursor are impacted until a vendor fix is applied. No specific version range is listed in the advisory; therefore any installation of PowerDNS Recursor should be regarded as vulnerable unless a patched binary is deployed.
Risk and Exploitability
The CVSS score of 3.7 indicates a low severity, and the EPSS score of less than 1% signals an unlikely exploitation likelihood. The vulnerability is not included in the CISA KEV catalog. Exploitation requires the ability to send specially crafted queries that trigger a wildcard CNAME or DNAME response, which can be achievable from remote sources. A successful attack would allow spoofed domain resolutions, potentially redirecting users or enabling phishing or man‑in‑the‑middle attacks.
OpenCVE Enrichment
Debian DSA