CVE-2019-18934 is a shell code execution vulnerability in Unbound versions 1.6.4 through 1.9.4, specifically within its ipsec module. This flaw allows an attacker to execute arbitrary shell code by sending a specially crafted answer, but only if Unbound was compiled with and is actively using the --enable-ipsecmod option. Rated as High severity (CVSS 7.3), it has a low attack complexity and requires no user interaction, potentially leading to low impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant media coverage, though it has seen some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.6.4, <= 1.9.4CPE matchmatch criteria | cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* | ||
31CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* | ||
15.1CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* | ||
15.2CPE matchmatch criteria | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.