
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-30192 is a DNS spoofing vulnerability in PowerDNS Recursor affecting instances configured to send EDNS Client Subnet (ECS) enabled queries. When ECS is enabled, an attacker has a statistically higher chance of successfully spoofing DNS answers compared to non-ECS queries, due to insufficient verification of data authenticity (CWE-345). The vulnerability was published on July 21, 2025, and affects PowerDNS Recursor versions prior to 5.0.12, 5.1.6, and 5.2.4. It carries a CVSS v3.1 base score of 7.5 (High) (Red Hat Advisory, ENISA EUVD).
The root cause is classified as CWE-345 (Insufficient Verification of Data Authenticity). When PowerDNS Recursor sends outgoing queries with ECS (EDNS Client Subnet) options, the additional subnet information included in the query increases the attack surface for off-path spoofing, as the attacker can more precisely predict or match query parameters to craft a forged response. The vulnerability is exploitable remotely without authentication or user interaction, targeting the DNS resolution path between the Recursor and upstream resolvers. The patched versions introduce mitigations including chaining ECS-enabled requests and enforcing stricter validation of received answers; the most stringent protection is activated by enabling the new outgoing.edns_subnet_harden setting (formerly edns-subnet-harden) (PowerDNS Advisory, Red Hat Bugzilla).
Successful exploitation could allow an attacker to poison the DNS cache of the affected Recursor, redirecting users to malicious destinations or enabling man-in-the-middle attacks against DNS-dependent services. The primary impact is on availability and integrity of DNS resolution — confidentiality is not directly affected. Downstream clients relying on the poisoned Recursor could be redirected to attacker-controlled infrastructure, potentially enabling phishing, credential theft, or interception of sensitive traffic (Red Hat Advisory, ENISA EUVD).
There is no public proof-of-concept exploit and no evidence of in-the-wild exploitation at this time. The EPSS score is approximately 0.009% (0.000090), indicating a very low probability of exploitation in the near term. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. No threat actor attribution has been reported (Feedly Intelligence).
Upgrade PowerDNS Recursor to one of the patched versions: 5.0.12, 5.1.6, or 5.2.4. After upgrading, enable the new outgoing.edns_subnet_harden setting (legacy name: edns-subnet-harden) for the strictest protection against ECS spoofing. As an interim measure, disabling ECS on outgoing queries eliminates the elevated spoofing risk. Additionally, deploying DNSSEC validation on the Recursor provides an independent layer of protection against forged DNS responses (PowerDNS Advisory, Red Hat Bugzilla).
Red Hat has tracked the vulnerability via Bugzilla and assigned it medium severity for their products. ENISA has catalogued the vulnerability in the EU Vulnerability Database (EUVD-2025-22089). No significant public researcher commentary or social media discussion has been identified beyond standard vulnerability aggregator coverage (Red Hat Advisory, ENISA EUVD).
Fix availability across major Linux distributions and their releases.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."