← Vulnerability feed

Vulnerability record · CVE-2015-5311 · published 17 November 2015

CVE-2015-5311: PowerDNS Authoritative Server crash via crafted query packets

Powerdns · Authoritative

PowerDNS Authoritative Server versions 3.4.4 up to but not including 3.4.7 fail to properly validate crafted query packets, triggering an assertion failure that crashes the server. Because the authoritative server is the DNS resolver of record for its zones, a crash takes those zones offline until the process restarts.

5.0 CVSS 2.0 Medium EPSS 67% · top 0.7% CWE-20 · Improper input validation
5.0CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
17 Jun 2026Last modified by NVD

Description

PowerDNS (aka pdns) Authoritative Server 3.4.4 before 3.4.7 allows remote attackers to cause a denial of service (assertion failure and server crash) via crafted query packets.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely exploitable without authentication and crashes a core DNS service, and the high EPSS score suggests active interest despite no KEV listing.

What it is

PowerDNS Authoritative Server versions 3.4.4 up to but not including 3.4.7 fail to properly validate crafted query packets, triggering an assertion failure that crashes the server. Because the authoritative server is the DNS resolver of record for its zones, a crash takes those zones offline until the process restarts.

Impact

A remote unauthenticated attacker can cause a denial of service by crashing the PowerDNS process, interrupting DNS resolution for all zones it serves. No data confidentiality or integrity impact is described; the effect is availability loss.

Attack surface

Reachable over the network via the DNS service port, as reflected by the AV:N/AC:L/Au:N vector. No authentication or user interaction is required; the attacker only needs to send a crafted query packet to the server.

Exploitation

Not listed in CISA KEV and no ransomware association is documented, but EPSS is high at roughly 0.67 (99th percentile), indicating elevated likelihood of exploitation activity. The vendor advisory is tagged Patch and Vendor Advisory, confirming a fix exists.

What to do

  • Upgrade PowerDNS Authoritative Server to 3.4.7 or later per the vendor advisory powerdns-advisory-2015-03.
  • If immediate upgrade is not possible, restrict DNS query access to trusted networks and clients via firewall or ACL rules.
  • Run the authoritative server under a supervisor or service manager that automatically restarts it after a crash to limit outage duration.
  • Monitor vendor and distribution package announcements for backported fixes if running a packaged build.

Detection

  • Monitor PowerDNS process logs for assertion failures or unexpected restarts and correlate with inbound query traffic.
  • Alert on abrupt termination or restart events of the pdns service outside planned maintenance windows.
  • Baseline DNS query patterns and flag unusual or malformed query packets directed at the authoritative server.
  • Track availability gaps in DNS responses for zones served by the affected instance.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2015-5311 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2026-33608Powerdns authoritative code injection vulnerabilityAn attacker can send a notify request that causes a new secondary domain to be added to the bind backend, but causes said backend to update its confi…EPSS 0.59%9.8CVE-2020-24698Powerdns authoritative double free vulnerabilityAn issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker might…EPSS 3.2%8.6CVE-2026-42000Powerdns authoritative command injection vulnerabilityInsufficient Validation of Names During AXFREPSS 0.54%8.1CVE-2020-24696Powerdns authoritative race condition vulnerabilityAn issue was discovered in PowerDNS Authoritative through 4.3.0 when --enable-experimental-gss-tsig is used. A remote, unauthenticated attacker can t…EPSS 1.4%7.8CVE-2015-5470Powerdns authoritative vulnerabilityThe label decompression functionality in PowerDNS Recursor before 3.6.4 and 3.7.x before 3.7.3 and Authoritative (Auth) Server before 3.3.3 and 3.4.x…EPSS 11%7.8CVE-2015-1868PowerDNS label decompression self-referential name denial of serviceThe label decompression code in PowerDNS Recursor (3.5.x, 3.6.x before 3.6.3, 3.7.x before 3.7.2) and Authoritative Server (3.2.x, 3.3.x before 3.3.2…EPSS 82%analysed7.5CVE-2026-42001Powerdns authoritative uncontrolled resource consumption vulnerabilityInsufficient Validation of Autoprimary SOA QueriesEPSS 0.80%7.5CVE-2026-42002Powerdns authoritative vulnerabilityConcurrency and locking defects in GSS-TSIGEPSS 0.58%

Source: NIST National Vulnerability Database (record CVE-2015-5311), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.