AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2017-15090

MEDIUM · CVSS 5.9 EPSS 0.61%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-01-23 · Last synced 2026-08-04

CyberRota Analysis

This is a medium severity vulnerability with a CVSS score of 5.9. See the original NVD description below for full technical details.

CVE
CVE-2017-15090
Severity
MEDIUM
CVSS
5.9
EPSS
0.61%

Original NVD Description

An issue has been found in the DNSSEC validation component of PowerDNS Recursor from 4.0.0 and up to and including 4.0.6, where the signatures might have been accepted as valid even if the signed data was not in bailiwick of the DNSKEY used to sign it. This allows an attacker in position of man-in-the-middle to alter the content of records by issuing a valid signature for the crafted records.

Related CVEs

Other vulnerabilities affecting the same vendor(s)