{"api_version":"1","generated_at":"2026-07-23T12:45:34+00:00","cve":"CVE-2022-33993","urls":{"html":"https://cve.report/CVE-2022-33993","api":"https://cve.report/api/cve/CVE-2022-33993.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-33993","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-33993"},"summary":{"title":"CVE-2022-33993","description":"Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form.","state":"PUBLIC","assigner":"cve@mitre.org","published_at":"2022-08-15 12:15:00","updated_at":"2022-08-18 17:48:00"},"problem_types":["NVD-CWE-noinfo"],"metrics":[],"references":[{"url":"http://dnrd.sourceforge.net/","name":"http://dnrd.sourceforge.net/","refsource":"MISC","tags":[],"title":"DNRD - Domain Name Relay Daemon","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.usenix.org/conference/usenixsecurity21/presentation/jeitner","name":"https://www.usenix.org/conference/usenixsecurity21/presentation/jeitner","refsource":"MISC","tags":[],"title":"Injection Attacks Reloaded: Tunnelling Malicious Payloads over DNS | USENIX","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.openwall.com/lists/oss-security/2022/08/14/1","name":"https://www.openwall.com/lists/oss-security/2022/08/14/1","refsource":"MISC","tags":[],"title":"oss-security - Multiple DNS Cache poisoning vulnerabilities in dnrd DNS forwarder\n (CVE-2022-33993, CVE-2022-33992)","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner","name":"https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner","refsource":"MISC","tags":[],"title":"XDRI Attacks - and - How to Enhance Resilience of Residential Routers | USENIX","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-33993","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-33993","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"33993","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"domain_name_relay_daemon_project","cpe5":"domain_name_relay_daemon","cpe6":"2.20.3","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2022-33993","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Misinterpretation of special domain name characters in DNRD (aka Domain Name Relay Daemon) 2.20.3 leads to cache poisoning because domain names and their associated IP addresses are cached in their misinterpreted form."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"url":"https://www.usenix.org/conference/usenixsecurity21/presentation/jeitner","refsource":"MISC","name":"https://www.usenix.org/conference/usenixsecurity21/presentation/jeitner"},{"url":"https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner","refsource":"MISC","name":"https://www.usenix.org/conference/usenixsecurity22/presentation/jeitner"},{"url":"http://dnrd.sourceforge.net/","refsource":"MISC","name":"http://dnrd.sourceforge.net/"},{"refsource":"MISC","name":"https://www.openwall.com/lists/oss-security/2022/08/14/1","url":"https://www.openwall.com/lists/oss-security/2022/08/14/1"}]}},"nvd":{"publishedDate":"2022-08-15 12:15:00","lastModifiedDate":"2022-08-18 17:48:00","problem_types":["NVD-CWE-noinfo"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"LOW","availabilityImpact":"NONE","baseScore":5.3,"baseSeverity":"MEDIUM"},"exploitabilityScore":3.9,"impactScore":1.4}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:domain_name_relay_daemon_project:domain_name_relay_daemon:2.20.3:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}