Unbound before 1.9.5 allows configuration injection in create_unbound_ad_servers.sh upon a successful man-in-the-middle attack against a cleartext HTTP session. NOTE: The vendor does not consider this a vulnerability of the Unbound software. create_unbound_ad_servers.sh is a contributed script from the community that facilitates automatic configuration creation. It is not part of the Unbound installation
CVSS Details
- CVSS 3.1 Base Score: 5.9
- CVSS 3.1 Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Debian | — | Upgrade unbound | May 10, 2021 | Apr 27, 2021 |
| Huawei Euleros 2_0_sp2 | — | Upgrade unboundUpgrade unbound-libs | Sep 16, 2021 | Apr 27, 2021 |
| Huawei Euleros 2_0_sp3 | — | Upgrade unboundUpgrade unbound-libs | Oct 26, 2021 | Apr 27, 2021 |
| Huawei Euleros 2_0_sp5 | — | Upgrade unboundUpgrade unbound-libs | Sep 7, 2021 | Apr 27, 2021 |
| Huawei Euleros 2_0_sp8 | — | Upgrade unboundUpgrade unbound-libsUpgrade python3-unboundUpgrade python2-unbound | Aug 10, 2021 | Apr 27, 2021 |
| Huawei Euleros 2_0_sp9 | — | Upgrade unbound-libsUpgrade unboundUpgrade python3-unbound | Aug 10, 2021 | Apr 27, 2021 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | Apr 27, 2021 |
| Suse | — | Upgrade libunbound2Upgrade unbound-muninUpgrade unbound-develUpgrade unbound-anchorUpgrade unboundUpgrade unbound-python | Jan 26, 2022 | Apr 27, 2021 |
| Ubuntu | — | Upgrade libunbound2Upgrade libunbound8Upgrade unbound | May 7, 2021 | Apr 27, 2021 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | Apr 27, 2021 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub