CVE-2019-25031Injection in Unbound

Severity
5.9MEDIUMNVD
EPSS
0.8%
top 25.73%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 24

Description

Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NExploitability: 2.2 | Impact: 3.6

Affected Packages2 packages

NVDnlnetlabs/unbound< 1.9.5
Debiannlnetlabs/unbound< 1.9.6-1+3

Also affects: Debian Linux 9.0

🔴Vulnerability Details

3
GHSA
GHSA-9vvw-9wr3-56v3: Unbound before 12022-05-24
OSV
CVE-2019-25031: Unbound before 12021-04-27
CVEList
CVE-2019-25031: Unbound before 12021-04-27

📋Vendor Advisories

3
Ubuntu
Unbound vulnerabilities2021-05-06
Red Hat
unbound: configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session2019-12-11
Debian
CVE-2019-25031: unbound - Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers...2019
CVE-2019-25031 — Injection in Nlnetlabs Unbound | cvebase