Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-29483

22
FAUCET Score

CVE-2023-29483 is a high-severity vulnerability affecting eventlet (before 0.35.2) and dnspython (before 2.6.0), allowing remote attackers to disrupt DNS resolution through a "TuDoor" attack by sending a malformed packet from the expected source. The attack has a high complexity (AC:H) but does not require user interaction (UI:N), potentially leading to limited confidentiality and integrity impact, but high availability impact (C:L/I:L/A:H). There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 0.35.2CPE matchmatch criteria
cpe:2.3:a:eventlet:eventlet:*:*:*:*:*:*:*:*
< 2.6.0CPE matchmatch criteria
cpe:2.3:a:dnspython:dnspython:*:*:*:*:*:*:*:*
38CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:38:*:*:*:*:*:*:*
39CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:39:*:*:*:*:*:*:*
40CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:40:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.0HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
LOW
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
4.7
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.86%
Probability of exploitation in next 30 days
EPSS Percentile
77.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0186 is in the 35th percentile among its peer group of 8,920 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (13)

pippatch availablevia ghsa
Product: eventletFixed in: 0.35.2
pippatch availablevia ghsa
Product: dnspythonFixed in: 2.6.1
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Automation Platform 2.4 for RHEL 8Fixed in: ansible-automation-platform-24/ee-supported-rhel8:1.0.0-661
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Ansible Automation Platform 2.4 for RHEL 9Fixed in: ansible-automation-platform-24/ee-supported-rhel9:1.0.0-660
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python-dns-0:1.15.0-12.el8_10
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: python-dns-0:2.6.1-3.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.13Fixed in: openshift4/ose-ironic-rhel9:v4.13.0-202407230838.p0.g0456ffe.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.14Fixed in: openshift4/ose-ironic-rhel9:v4.14.0-202407301840.p0.g2d4e89c.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.15Fixed in: openshift4/ose-ironic-rhel9:v4.15.0-202407181606.p0.gea6d005.assembly.stream.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift Container Platform 4.16Fixed in: python-eventlet-0:0.33.1-6.el9
View patch
redhatno patchvia redhat_api
Product: Red Hat Ansible Automation Platform 2Fixed in: aap-cloud-metrics-collector-container
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: python27:2.7/python-dns
redhatend of lifevia redhat_api
Product: Red Hat OpenStack Platform 17.1Fixed in: python-eventlet

Vendor Advisories (2)

pipGHSA-3rq5-2g8h-59hcmedium

Potential DoS via the Tudoor mechanism in eventlet and dnspython

Apr 11, 2024
redhatCVE-2023-29483Moderate

dnspython: denial of service in stub resolver

Feb 9, 2024

References

lists.fedoraproject.org / archives/list/[email protected]/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6
lists.fedoraproject.org / archives/list/[email protected]/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH
github.com / eventlet/eventlet/issues/913
ExploitIssue Tracking
github.com / eventlet/eventlet/releases/tag/v0.35.2
Release Notes
github.com / rthalley/dnspython/issues/1045
ExploitIssue Tracking
github.com / rthalley/dnspython/releases/tag/v2.6.0
Release Notes
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/NLRKR57IFVKQC2GCXZBFLCLBAWBWL3F6
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/VOHJOO3OM65UIUUUVDEXMCTXNM6LXZEH
Mailing List
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/X3BNSIK5NFYSAP53Y45GOCMOQHHDLGIF
Mailing List
security.netapp.com / advisory/ntap-20240510-0001
Third Party Advisory
security.snyk.io / vuln/SNYK-PYTHON-DNSPYTHON-6241713
Third Party Advisory
dnspython.org
Product