An issue was discovered in Technitium through 11.0.3. It enables attackers to conduct a DNS cache poisoning attack and inject fake responses within 1 second, which is impactful.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://technitium.com/dns/ | product |
https://gist.github.com/idealeer/89947ca07836fd0f7e9761198ca9a0f3 | third party advisory |