CVE-2020-12667: Nic Knot Resolver

High severity, CVSS 7.5. EPSS: 2.6% chance of exploitation in the next 30 days.

Knot Resolver before 5.1.1 allows traffic amplification via a crafted DNS answer from an attacker-controlled server, aka an "NXNSAttack" issue. This is triggered by random subdomains in the NSDNAME in NS records.

Affected products

  • Nic Knot Resolver: before 5.1.1 (fixed in 5.1.1)

Published 2020-05-19. Last modified 2026-06-17.