Row breaks out over true severity of two DNSSEC flaws
ID: 2ab1acf6-095a-58a7-aa79-0e62880cdcc0
STIX ID: report--2ab1acf6-095a-58a7-aa79-0e62880cdcc0
Feed Name: The Register (Security)
Threat Score
The article contrasts two DNSSEC vulnerabilities—KeyTrap (CVE-2023-50387), which ATHENE research indicates can produce extreme CPU exhaustion and enable large-scale DNS resolver denial-of-service, and NSEC3-encloser (CVE-2023-50868), which appears orders of magnitude less severe—while raising concerns about MITRE/NIST CVE descriptions and the accuracy of CVSS scoring.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
