CVE-2025-40778: falha de alta gravidade em ISC BIND 9
Cache poisoning attacks with unsolicited RRs
Publicada em · Atualizada em
21Vexday Risk Score
Sem sinal de exploração. Nenhum artefato público de exploração conhecido até agora.
ssvc Trackcvss 8.6epss 0.7%
probabilidade de exploração
0.7%top 50% das CVEs
exploração observada
nãonenhuma fonte reporta
Under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
This issue affects BIND 9 versions 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N
Produtos afetados
ISC · BIND 9CVEs relacionadas — ISC BIND 9
No mesmo produto, das mais perigosas para as menos.
CVE-2018-5740HIGHA flaw in the "deny-answer-aliases" feature can cause an assertion failure in namedEPSS 59.6%CVE-2022-3736HIGHnamed configured to answer from stale cache may terminate unexpectedly while processing RRSIG queriesEPSS 48.7%CVE-2017-3145HIGHImproper fetch cleanup sequencing in the resolver can cause named to crashEPSS 27.9%CVE-2022-3488HIGHnamed may terminate unexpectedly when processing ECS options in repeated responses to iterative queriesEPSS 19.2%CVE-2024-12705HIGHDNS-over-HTTPS implementation suffers from multiple issues under heavy query loadEPSS 18.4%CVE-2017-3143HIGHAn error in TSIG authentication can permit unauthorized dynamic updatesEPSS 18.3%