CVE-2022-3204, dubbed the 'Non-Responsive Delegation Attack' (NRDelegation Attack), affects various DNS resolving software, including Unbound and Fedora's DNS resolvers. This vulnerability allows an attacker to craft a malicious DNS delegation with numerous unresponsive nameservers, causing resolvers to expend significant resources and time attempting to resolve records under this delegation. The attack has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity that can lead to high availability impact, potentially resulting in degraded performance and denial of service. While Unbound versions 1.16.3 and later include fixes to mitigate this, the vulnerability is not currently known to be actively exploited, nor is there publicly available exploit code or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.16.2CPE match | cpe:2.3:a:nlnetlabs:unbound:*:*:*:*:*:*:*:* | ||
35CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:* | ||
36CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:* | ||
37CPE matchmatch criteria | cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.