Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-7008


A vulnerability was found in systemd-resolved. This issue may allow systemd-resolved to accept records of DNSSEC-signed domains even when they have no signature, allowing man-in-the-middles (or the upstream DNS resolver) to manipulate records.


Published

2023-12-23T13:15:07.573

Last Modified

2024-11-22T12:15:17.590

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 5.9 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-300
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application systemd_project systemd 25 Yes
Operating System debian debian_linux 8.0 No
Operating System debian debian_linux 9.0 No

References