CVE-2023-28457

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
18/09/2024
Last modified:
22/04/2025

Description

An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:technitium:dnsserver:*:*:*:*:*:*:*:* 11.0.3 (including)