The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
The issue is a DNSSEC validation bypass where wildcard expansion proofs (NSEC/NSEC3 records) are accepted without signature validation when the wildcard answer is a CNAME or DNAME record.
Why this VPI (explainable, experimental)
VPI breakdown
| Impact | 37.00 |
| Exploitation signal(No additional exploitation signal) | ×1.00 |
| VPI | 37.00 |
VPI formula vpi-v1