Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-25215


In BIND 9.0.0 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a query for a record triggering the flaw described above, the named process will terminate due to a failed assertion check. The vulnerability affects all currently maintained BIND 9 branches (9.11, 9.11-S, 9.16, 9.16-S, 9.17) as well as all other versions of BIND 9.


Published

2021-04-29T01:15:08.013

Last Modified

2024-11-21T05:54:33.650

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 7.5 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:N/C:N/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: NONE
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

10.0

Impact Score

2.9

Weaknesses
  • Type: Primary
    CWE-617

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Operating System debian debian_linux 9.0 Yes
Operating System debian debian_linux 10.0 Yes
Application isc bind < 9.11.31 Yes
Application isc bind < 9.16.15 Yes
Application isc bind < 9.17.12 Yes
Application isc bind 9.9.3 Yes
Application isc bind 9.9.12 Yes
Application isc bind 9.9.13 Yes
Application isc bind 9.10.5 Yes
Application isc bind 9.10.7 Yes
Application isc bind 9.11.3 Yes
Application isc bind 9.11.5 Yes
Application isc bind 9.11.5 Yes
Application isc bind 9.11.5 Yes
Application isc bind 9.11.6 Yes
Application isc bind 9.11.7 Yes
Application isc bind 9.11.8 Yes
Application isc bind 9.11.12 Yes
Application isc bind 9.11.21 Yes
Application isc bind 9.11.27 Yes
Application isc bind 9.11.29 Yes
Application isc bind 9.16.8 Yes
Application isc bind 9.16.11 Yes
Application isc bind 9.16.13 Yes
Operating System fedoraproject fedora 33 Yes
Operating System fedoraproject fedora 34 Yes
Application netapp active_iq_unified_manager - Yes
Application netapp cloud_backup - Yes
Operating System netapp h300s_firmware - Yes
Hardware netapp h300s - No
Operating System netapp h500s_firmware - Yes
Hardware netapp h500s - No
Operating System netapp h700s_firmware - Yes
Hardware netapp h700s - No
Operating System netapp h300e_firmware - Yes
Hardware netapp h300e - No
Operating System netapp h500e_firmware - Yes
Hardware netapp h500e - No
Operating System netapp h700e_firmware - Yes
Hardware netapp h700e - No
Operating System netapp h410s_firmware - Yes
Hardware netapp h410s - No
Operating System netapp a250_firmware - Yes
Hardware netapp a250 - No
Operating System netapp 500f_firmware - Yes
Hardware netapp 500f - No
Application oracle tekelec_platform_distribution ≤ 7.7.1 Yes
Application siemens sinec_infrastructure_network_services < 1.0.1.1 Yes

References