An attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its configuration to an invalid one, leading to the backend no longer able to run on the next restart, requiring manual operation to fix it.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:HPowerdns Authoritative
APPPowerdns4.9.0 – 4.9.14 (excl.)5.0.0 – 5.0.4 (excl.)
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
Related vulnerabilities
CVE-2020-24698CRITICAL9.8PL ✓same product
PowerDNS Authoritative: double-free via GSS-TSIG umożliwia RCE
CVE-2026-42001HIGH7.5same product
Insufficient Validation of Autoprimary SOA Queries
CVE-2020-24697HIGH7.5same product
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A...
CVE-2020-24696HIGH8.1same product
An issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A...
CVE-2015-5230HIGH7.5same product
The DNS packet parsing/generation code in PowerDNS (aka pdns) Authoritative Server 3.4.x before 3.4.6 allows r...