← All CVEs

CVE-2020-8625

high · 8.1

BIND servers are vulnerable if they are running an affected version and are configured to use GSS-TSIG features. In a configuration which uses BIND's default settings the vulnerable code path is not exposed, but a server can be rendered vulnerable by explicitly setting valid values for the tkey-gssapi-keytab or tkey-gssapi-credentialconfiguration options. Although the default configuration is not vulnerable, GSS-TSIG is frequently used in networks where BIND is integrated with Samba, as well as in mixed-server environments that combine BIND servers with Active Directory domain controllers. The most likely outcome of a successful exploitation of the vulnerability is a crash of the named process. However, remote code execution, while unproven, is theoretically possible. Affects: BIND 9.5.0 -> 9.11.27, 9.12.0 -> 9.16.11, and versions BIND 9.11.3-S1 -> 9.11.27-S1 and 9.16.8-S1 -> 9.16.11-S1 of BIND Supported Preview Edition. Also release versions 9.17.0 -> 9.17.1 of the BIND 9.17 development branch

8.1
CVSS
64.2%
EPSS (exploit prob.)
99th
EPSS percentile
2021-02-17
Published

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-120

Affected products

VendorProductAffected versions
iscbind>= 9.5.0, <= 9.11.27
iscbind>= 9.12.0, <= 9.16.11
iscbind9.11.3
iscbind9.11.5
iscbind9.11.5
iscbind9.11.6
iscbind9.11.7
iscbind9.11.8
iscbind9.11.21
iscbind9.11.27
iscbind9.16.8
iscbind9.16.11
iscbind9.17.0
iscbind9.17.1
debiandebian_linux9.0
debiandebian_linux10.0
fedoraprojectfedora32
fedoraprojectfedora33
fedoraprojectfedora34
siemenssinec_infrastructure_network_services< 1.0.1.1
netappcloud_backupall versions
netappa250_firmwareall versions
netappa250all versions
netapp500f_firmwareall versions
netapp500fall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2020-8625