The DNS C2 listener accepts unauthenticated TOTP bootstrap messages and allocates server-side DNS sessions without validating OTP values, even when EnforceOTP is enabled. Because sessions are stored without a cleanup/expiry path in this flow, an unauthenticated remote actor can repeatedly create sessions and drive memory exhaustion.
server/c2/dns.go:84-90 (EnforceOTP stored but not enforced in bootstrap)server/c2/dns.go:378-390 (TOTP requests routed directly to bootstrap)server/c2/dns.go:490-521 (handleHello allocates session without OTP validation)server/c2/dns.go:495 (sessions.Store with no lifecycle control in this path)client/command/jobs/dns.go:46-52 (operator-facing EnforceOTP control implies auth gate)implant/sliver/transports/dnsclient/dnsclient.go:896-900 (otpMsg sends TOTP with ID=0)protobuf/dnspb/dns.proto:22 (documents TOTP in ID field)DNSMessageType_TOTP bootstrap handlingTOTP.while true; do
dig +short @<DNS_C2_IP> baa8.<parent-domain> A >/dev/null
done
baa8 is a base32 payload for a minimal TOTP-type protobuf message.
handleHelloCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H (7.5 High){
"cwe_ids": [
"CWE-306",
"CWE-400"
],
"github_reviewed": true,
"github_reviewed_at": "2026-02-06T22:52:00Z",
"nvd_published_at": "2026-02-09T21:15:49Z",
"severity": "HIGH"
}