« Volver al listado

CVE-2026-0397

Estado: AnalizadaMedia (4.3)—

When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2026-0397",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2026-0397",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-03-31T13:19:54.934769Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@open-xchange.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 3.1,
          "attackVector": "NETWORK",
          "baseSeverity": "LOW",
          "vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "HIGH",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 1.6
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 4.3,
          "attackVector": "NETWORK",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 1.4,
        "exploitabilityScore": 2.8
      }
    ]
  },
  "affected": [
    {
      "source": "security@open-xchange.com",
      "affectedData": [
        {
          "repo": "https://github.com/PowerDNS/pdns",
          "vendor": "PowerDNS",
          "modules": [
            "Internal Web Server"
          ],
          "product": "DNSdist",
          "versions": [
            {
              "status": "affected",
              "version": "1.9.0",
              "lessThan": "1.9.12",
              "versionType": "semver"
            },
            {
              "status": "affected",
              "version": "2.0.0",
              "lessThan": "2.0.3",
              "versionType": "semver"
            }
          ],
          "packageName": "dnsdist",
          "programFiles": [
            "dnsdist-web.cc"
          ],
          "collectionURL": "https://repo.powerdns.com/",
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2026-03-31T12:16:27.340",
  "references": [
    {
      "url": "https://www.dnsdist.org/security-advisories/powerdns-advisory-for-dnsdist-2026-02.html",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@open-xchange.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
      "description": [
        {
          "lang": "en",
          "value": "CWE-942"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "When the internal webserver is enabled (default is disabled), an attacker might be able to trick an administrator logged to the dashboard into visiting a malicious website and extract information about the running configuration from the dashboard. The root cause of the issue is a misconfiguration of the Cross-Origin Resource Sharing (CORS) policy."
    },
    {
      "lang": "es",
      "value": "Cuando el servidor web interno está habilitado (por defecto está deshabilitado), un atacante podría engañar a un administrador que ha iniciado sesión en el panel de control para que visite un sitio web malicioso y extraiga información sobre la configuración en ejecución del panel de control. La causa raíz del problema es una configuración incorrecta de la política de Intercambio de Recursos de Origen Cruzado (CORS)."
    }
  ],
  "lastModified": "2026-07-25T10:10:00.167",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "628B3B94-81DE-496E-B36A-B79A3DFFE1F4",
              "versionEndExcluding": "1.9.12",
              "versionStartIncluding": "1.9.0"
            },
            {
              "criteria": "cpe:2.3:a:powerdns:dnsdist:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9AC850DD-FDD8-4C48-B861-4BBAF423FF57",
              "versionEndExcluding": "2.0.3",
              "versionStartIncluding": "2.0.0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@open-xchange.com"
}