MEDIUM · 6.8

CVE-2021-25220

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, ...

Vulnerability Description

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.

CVSS Score

6.8

MEDIUM

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
CHANGED
Confidentiality
NONE
Integrity
HIGH
Availability
NONE

Affected Products

VendorProductVersions
IscBind>= 9.11.0, < 9.11.37
FedoraprojectFedora34
NetappH300S Firmware-
NetappH300S-
NetappH500S Firmware-
NetappH500S-
NetappH700S Firmware-
NetappH700S-
NetappH300E Firmware-
NetappH300E-
NetappH500E Firmware-
NetappH500E-
NetappH700E Firmware-
NetappH700E-
NetappH410S Firmware-
NetappH410S-
NetappH410C Firmware-
NetappH410C-
SiemensSinec Ins< 1.0
JuniperJunos< 19.3

Related Weaknesses (CWE)

References

FAQ

What is CVE-2021-25220?

CVE-2021-25220 is a vulnerability with a CVSS score of 6.8 (MEDIUM). BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, ...

How severe is CVE-2021-25220?

CVE-2021-25220 has been rated MEDIUM with a CVSS base score of 6.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2021-25220?

Check the references section above for vendor advisories and patch information. Affected products include: Isc Bind, Fedoraproject Fedora, Netapp H300S Firmware, Netapp H300S, Netapp H500S Firmware.