(01) - CybersecurityDMSA-2025-ES-001
Subdomain Vulnerability in Spanish DGT Domain
A misconfiguration in subdomain management for dgt.es was discovered, potentially allowing attackers to host malicious content under official-looking subdomains.
Executive Summary
Dymo's automated security scanning detected a subdomain misconfiguration vulnerability in the Spanish Directorate General of Traffic (DGT) domain (dgt.es). This flaw could enable attackers to create malicious subdomains that appear to originate from the official government domain.
Affected Entity
- Organization: Dirección General de Tráfico (DGT)
- Country: Spain
- Domain: dgt.es
- Function: Traffic regulation and road safety
Vulnerability Details
Type
DNS Subdomain Misconfiguration / Wildcard Abuse
Severity
Medium-High (CVSS 6.1)
Technical Analysis
The vulnerability exists due to:
- Improper DNS Configuration: Wildcard records allowing arbitrary subdomain creation
- Missing Validation: No verification of legitimate subdomain ownership
- SSL Gaps: Certificates not enforced on all subdomains
- Lack of Monitoring: No detection of unauthorized subdomain creation
Attack Scenarios
Exploitation could result in:
- Phishing Sites: Fake DGT portals for credential theft
- Malware Distribution: Host malicious downloads on trusted domain
- Email Spoofing: Bypass SPF/DKIM using subdomain
- Service Impersonation: Fake payment or appointment scheduling sites
Impact
Given DGT's role in vehicle registration, driver licensing, and traffic fines:
- High-value targets: Vehicle owners, driving schools, transport companies
- Trust exploitation: Users expect official government URLs
- Financial fraud: Fake fine payment portals
- Data harvesting: Personal and vehicle information collection
Responsible Disclosure
Reported to:
- DGT IT Security Team
- INCIBE (Instituto Nacional de Ciberseguridad)
- Spanish Ministry of Interior
Recommended Mitigations
- Restrict wildcard DNS entries
- Implement CAA records for SSL certificates
- Deploy subdomain monitoring solutions
- Enable certificate transparency logging
- Regular DNS configuration audits
This vulnerability was identified through Dymo's continuous government sector scanning.