
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2020-12667 affects Knot Resolver versions before 5.1.1, allowing traffic amplification via a crafted DNS answer from an attacker-controlled server, known as an 'NXNSAttack' issue. The vulnerability was discovered in May 2020 and is triggered by random subdomains in the NSDNAME in NS records (NVD, Knot Resolver).
The vulnerability exploits the DNS delegation mechanism to force DNS resolvers to generate multiple DNS queries to authoritative servers of the attacker's choice. The attack uses glueless delegation, where the resolver receives only names of authoritative DNS servers without their IP addresses, forcing additional queries. The packet amplification factor (PAF) varies by implementation - BIND 9.12.3 resolver showed a PAF of 1000x, while Knot Resolver 5.1.0 limited it to the order of tens (CZ NIC Blog).
The vulnerability enables attackers to use standard-compliant DNS resolvers as amplifiers for random subdomain attacks, potentially leading to significant traffic amplification and denial of service conditions. The attack's effectiveness varies based on the resolver implementation and its resource capacity (CZ NIC Blog).
The vulnerability can be exploited by sending a DNS query to a vulnerable resolver and providing a specially crafted answer from an authoritative server under attacker's control. This DNS protocol vulnerability affects most recursive DNS resolvers, making it a widespread issue (OSS Security).
The primary mitigation is upgrading to Knot Resolver version 5.1.1 or later, which includes specific protections against this attack. The fix implements limits on the number of names resolved when processing a single delegation. Additionally, deploying DNSSEC and enabling Aggressive Use of DNSSEC-Validated Cache (RFC 8198) can help limit the impact of random subdomain attacks (CZ NIC Blog, Knot Resolver).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."