Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2020-25686

19
FAUCET Score

CVE-2020-25686 is a flaw in dnsmasq, affecting versions prior to 2.83, including products from Arista, Debian, Fedora, and TheKelleys. This vulnerability allows an off-path attacker to significantly reduce the effort required to forge DNS replies and poison the dnsmasq cache due to the software not checking for existing pending requests for the same name. The attack has a low severity CVSS score of 3.7, with high attack complexity, and primarily impacts data integrity. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered significant community discussion and media coverage, indicating awareness and potential for future exploitation.

Impacted Technologies

VendorProductVersion(s)CPE
< 2.83CPE matchmatch criteria
cpe:2.3:a:thekelleys:dnsmasq:*:*:*:*:*:*:*:*
32CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:*
33CPE matchmatch criteria
cpe:2.3:o:fedoraproject:fedora:33:*:*:*:*:*:*:*
10.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*
>= 4.21, < 4.21.14mCPE matchmatch criteria
cpe:2.3:o:arista:eos:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

3.7LOW

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
LOW
Availability Impact
NONE
Exploitability Score
2.2
Impact Score
1.4
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.87%
Probability of exploitation in next 30 days
EPSS Percentile
91.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0487 is in the 91st percentile among its peer group of 1,506 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (16)

microsoftpatch availablevia msrc
Product: 19065-16820Fixed in: 2.85-1
microsoftpatch availablevia msrc
Product: cm1 dnsmasq 2.85-1 on CBL Mariner 1.0Fixed in: 2.85-1
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.2 Advanced Update SupportFixed in: dnsmasq-0:2.66-14.el7_2.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.3 Advanced Update SupportFixed in: dnsmasq-0:2.66-21.el7_3.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Advanced Update SupportFixed in: dnsmasq-0:2.76-2.el7_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Telco Extended Update SupportFixed in: dnsmasq-0:2.76-2.el7_4.3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.4 Update Services for SAP SolutionsFixed in: dnsmasq-0:2.76-2.el7_4.3
View patch
redhatpatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.7 Extended Update SupportFixed in: dnsmasq-0:2.76-10.el7_7.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: dnsmasq-0:2.79-13.el8_3.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.1 Extended Update SupportFixed in: dnsmasq-0:2.79-6.el8_1.1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8.2 Extended Update SupportFixed in: dnsmasq-0:2.79-11.el8_2.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 7Fixed in: redhat-virtualization-host-0:4.3.13-20210127.0.el7_9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Virtualization 4 for Red Hat Enterprise Linux 8Fixed in: redhat-virtualization-host-0:4.4.4-20210201.0.el8_3
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7.6 Extended Update SupportFixed in: dnsmasq-0:2.76-7.el7_6.2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: dnsmasq-0:2.76-16.el7_9.1
View patch

Vendor Advisories (2)

redhatCVE-2020-25686Moderate

dnsmasq: multiple queries forwarded for the same name makes forging replies easier for an off-path attacker

Jan 19, 2021
microsoft2021-Jan/CVE-2020-25686Low

A flaw was found in dnsmasq before version 2.83. When receiving a query dnsmasq does not check for an existing pending request for the same name and forwards a new request. By default a maximum of 150 pending queries can be sent to upstream servers so there can be at most 150 queries for the same name. This flaw allows an off-path attacker on the network to substantially reduce the number of attempts that it would have to perform to forge a reply and have it accepted by dnsmasq. This issue is mentioned in the "Birthday Attacks" section of RFC5452. If chained with CVE-2020-25684 the attack complexity of a successful attack is reduced. The highest threat from this vulnerability is to data integrity.

Jan 12, 2021

References

kb.cert.org / vuls/id/434904
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/QGB7HL3OWHTLEPSMLDGOMXQKG3KM2QME
lists.fedoraproject.org / archives/list/package-announce%40lists.fedoraproject.org/message/WYW3IR6APUSKOYKL5FT3ACTIHWHGQY32
security.gentoo.org / glsa/202101-17
Third Party Advisory
arista.com / en/support/advisories-notices/security-advisories/12135-security-advisory-61
Third Party Advisory
debian.org / security/2021/dsa-4844
Third Party Advisory
jsof-tech.com / disclosures/dnspooq
Third Party Advisory