ISC Kea
cpe:2.3:a:isc:kea:*:*:*:*:*:*:*
- 3.0.1
- 3.1.1
- 3.1.2
A denial-of-service vulnerability has been identified in ISC Kea versions 3.0.1 and 3.1.1 through 3.1.2. The issue arises in the Kea DHCPv4 server when specific configuration parameters are set in a certain way. To trigger the vulnerability, the 'hostname-char-set' must be left at its default value, the 'hostname-char-replacement' must be empty, and the 'ddns-qualifying-suffix' must not be empty. When these conditions are met, a client can send certain option content that causes the kea-dhcp4 server to exit unexpectedly.
Exploitation of this vulnerability leads to an unexpected termination of the Kea DHCP server, causing a denial-of-service condition.
Users can upgrade to Kea versions 3.0.2 or 3.1.3 to address this vulnerability. As an alternative workaround, the 'hostname-char-replacement' option can be set to any value other than empty, such as 'x'.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.