CyberRota Analysis
AI-GeneratedNLnet Labs Unbound versions 1.7.0 through 1.25.1 are vulnerable to a flaw that allows an attacker to spoof a hostname's A/AAAA record, potentially designating themselves as a primary transfer (XFR) endpoint for an auth/rpz zone. This could enable the attacker to replace the entire zone or modify the resolver's response policy, leading to significant disruptions in DNS resolution. Organizations using affected versions of Unbound should prioritize patching to mitigate the risk of unauthorized DNS manipulation.
Original NVD Description
In NLnet Labs Unbound 1.7.0 up to and including 1.25.1, when an auth/rpz zone has a configured primary hostname that resolves to BOGUS A/AAAA, it is still considered as a possible XFR endpoint. A malicious actor that can spoof the hostname's A/AAAA record (no valid RRSIG required) becomes the zone's XFR primary and can replaces the entire zone/the resolver's entire response policy.
Related CVEs
Other vulnerabilities affecting the same vendor(s)