AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2023-50387

HIGH · CVSS 7.5 EPSS 100.00%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2024-02-14 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.5. Its EPSS score suggests a 100.0% probability of exploitation in the next 30 days. It may be remotely exploitable. It may lead to a denial-of-service condition.

CVE
CVE-2023-50387
Severity
HIGH
CVSS
7.5
EPSS
100.00%

Original NVD Description

Certain DNSSEC aspects of the DNS protocol (in RFC 4033, 4034, 4035, 6840, and related RFCs) allow remote attackers to cause a denial of service (CPU consumption) via one or more DNSSEC responses, aka the "KeyTrap" issue. One of the concerns is that, when there is a zone with many DNSKEY and RRSIG records, the protocol specification implies that an algorithm must evaluate all combinations of DNSKEY and RRSIG records.

Related CVEs

Other vulnerabilities affecting the same vendor(s)