5
CVSSv2

CVE-2019-10191

Published: 16/07/2019 Updated: 12/02/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

A vulnerability exists in DNS resolver of knot resolver before version 4.1.0 which allows remote malicious users to downgrade DNSSEC-secure domains to DNSSEC-insecure state, opening possibility of domain hijack using attacks against insecure DNS protocol.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

nic knot resolver

fedoraproject fedora 29

fedoraproject fedora 30

Vendor Advisories

Debian Bug report logs - #932048 knot-resolver: CVE-2019-10190 CVE-2019-10191 Package: src:knot-resolver; Maintainer for src:knot-resolver is knot-resolver packagers <knot-resolver@packagesdebianorg>; Reported by: Salvatore Bonaccorso <carnil@debianorg> Date: Sun, 14 Jul 2019 12:09:02 UTC Severity: grave Tags: sec ...