peter bassill · operator
$ cve CVE-2020-8617 JSON

CVE-2020-8617 EXPLOIT

7.5
HIGH · CVSS 3.1 · EPSS 93.4% (pctl 100)

Patch early

A public exploit exists.

Description

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.

Scoring

CVSS7.5 (HIGH, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS93.42% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-617
On CISA KEVno
Public exploityes
Published2020-05-19
Last modified2026-06-17

Affected (5)

VendorProduct
canonicalubuntu linux
debiandebian linux
fedoraprojectfedora
iscbind
opensuseleap

Public exploits

SourceTitleDate
exploit-dbBIND - 'TSIG' Denial of Service2020-05-20

References

→ the Explorer  ·  watch your stack  ·  NVD