216.73.216.233

CVE-2025-30192

· Published 21/07/2025 13:15 · Modified 22/07/2025 13:06

Labels: CVE-2025-30192 2025-07-21CVE-2025-30192CWE-345[email protected]

Essential information

Published
21/07/2025 13:15
Modified
22/07/2025 13:06
Author
Creator
CVSS
7.5 HIGH (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

CVSS metrics

Description

An attacker spoofing answers to ECS enabled requests sent out by the Recursor has a chance of success higher than non-ECS enabled queries. The updated version include various mitigations against spoofing attempts of ECS enabled queries by chaining ECS enabled requests and enforcing stricter validation of the received answers. The most strict mitigation done when the new setting outgoing.edns_subnet_harden (old style name edns-subnet-harden) is enabled.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
open-xchange / recursor cpe:2.3:a:open-xchange:recursor:*:*:*:*:*:*:*:*

References