Loading...
Loading...
When a client sends a DNS request to a non-EDNS-capable server, the server may send a legitimate response with RCODE FORMERR and no DNS data. The MALFORM DNS vector blocks those requests if the dns-qdcount-limit vector is enabled.
AFM erroneously detects an attack and mitigates it, and the client does not get a response from the EDNS server
-- The client sends a DNS request to NON-EDNS capable server. -- The server replies with RCODE FORMERR and no DNS data. -- The dns-qdcount-limit vector is enabled.
Disable dns-qdcount-limit vector: security dos device-config /Common/dos-device-config { dos-device-vector { dns-nxdomain-query { state disabled } } }
Non-EDNS response with RCODE FORMERR are now processed as expected when the dns-qdcount-limit vector is enabled.
Click on a version to see all relevant bugs
F5 Integration
Learn more about where this data comes from
BugZero Plan
Streamline upgrades with automated vendor bug scrubs
BugZero Prevent
Wish you caught this bug sooner? Get proactive today.