Knot Resolver
Vendor:
First CVE: Jan 22, 2018 · Active for 8 years
14
Total CVEs
More Total CVEs than 91% of tracked products
2.0
Avg CVEs / Year
Higher CVE frequency than 60% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 40% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Knot Resolver over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 22, 2018
8 years ago
Most Recent CVE
Feb 14, 2024
891 days ago
CVE Severity & Scoring
Knot Resolver14 CVEs
21%
71%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHigh
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low11 (78.6%)
High3 (21.4%)
Unknown0 (0.0%)
User Interaction
None14 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low0 (0.0%)
High0 (0.0%)
None14 (100.0%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-50387HIGH Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more D | Feb 14, 2024 | 7.5 | 78 | NO | NO |
CVE-2022-40188HIGH Knot Resolver before 5.5.3 allows remote attackers to cause a denial of service (CPU consumption) because of algorithmic complexity. During an attack, an authoritative server must | Sep 23, 2022 | 7.5 | 27 | NO | NO |
CVE-2019-19331HIGH knot-resolver before version 4.3.0 is vulnerable to denial of service through high CPU utilization. DNS replies with very many resource records might be processed very inefficientl | Dec 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10191HIGH A vulnerability was discovered in DNS resolver of knot resolver before version 4.1.0 which allows remote attackers to downgrade DNSSEC-secure domains to DNSSEC-insecure state, open | Jul 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2019-10190HIGH A vulnerability was discovered in DNS resolver component of knot resolver through version 3.2.0 before 4.1.0 which allows remote attackers to bypass DNSSEC validation for non-exist | Jul 16, 2019 | 7.5 | 25 | NO | NO |
CVE-2021-40083HIGH Knot Resolver before 5.3.2 is prone to an assertion failure, triggerable by a remote attacker in an edge case (NSEC3 with too many iterations used for a positive wildcard proof). | Aug 25, 2021 | 7.5 | 24 | NO | NO |
CVE-2018-1110HIGH A flaw was found in knot-resolver before version 2.3.0. Malformed DNS messages may cause denial of service. | Mar 30, 2021 | 7.5 | 24 | NO | NO |
CVE-2023-26249HIGH Knot Resolver before 5.6.0 enables attackers to consume its resources, launching amplification attacks and potentially causing a denial of service. Specifically, a single client qu | Feb 21, 2023 | 7.5 | 23 | NO | NO |
CVE-2023-46317HIGH Knot Resolver before 5.7.0 performs many TCP reconnections upon receiving certain nonsensical responses from servers. | Oct 22, 2023 | 7.5 | 21 | NO | NO |
CVE-2020-12667HIGH Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomai | May 19, 2020 | 7.5 | 20 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For Knot Resolver
Top CWEs
Versions
No cataloged versions.