MEDIUM · 6.5

CVE-2020-8622

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or...

Vulnerability Description

In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or operating the server receiving the TSIG-signed request, could send a truncated response to that request, triggering an assertion failure, causing the server to exit. Alternately, an off-path attacker would have to correctly guess when a TSIG-signed request was sent, along with other characteristics of the packet and message, and spoof a truncated response to trigger an assertion failure, causing the server to exit.

CVSS Score

6.5

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
NONE
Integrity
NONE
Availability
HIGH

Affected Products

VendorProductVersions
IscBind>= 9.0.0, <= 9.11.21
FedoraprojectFedora31
DebianDebian Linux9.0
CanonicalUbuntu Linux12.04
NetappSteelstore Cloud Integrated Storage-
OpensuseLeap15.1
SynologyDns Server< 2.2.2-5028
OracleCommunications Diameter Signaling Router>= 8.0.0, <= 8.5.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2020-8622?

CVE-2020-8622 is a vulnerability with a CVSS score of 6.5 (MEDIUM). In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3, also affects 9.9.3-S1 -> 9.11.21-S1 of the BIND 9 Supported Preview Edition, An attacker on the network path for a TSIG-signed request, or...

How severe is CVE-2020-8622?

CVE-2020-8622 has been rated MEDIUM with a CVSS base score of 6.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2020-8622?

Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind, Fedoraproject Fedora, Debian Debian Linux, Canonical Ubuntu Linux, Netapp Steelstore Cloud Integrated Storage.