CVE-2020-8617

MEDIUMCVSS 5.9/10EPSS 93.42%

Last modified

CVE-2020-8617 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. EPSS estimates a 93.42% chance of exploitation in the next 30 days.

Description

Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.

Metrics

CVSS 3.1
5.9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
93.42%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
IscBind>= 9.0.0, <= 9.11.18
IscBind>= 9.12.0, <= 9.12.4
IscBind>= 9.13.0, <= 9.13.7
IscBind>= 9.14.0, <= 9.14.11
IscBind>= 9.15.0, <= 9.15.6
IscBind>= 9.16.0, <= 9.16.2
IscBind>= 9.17.0, <= 9.17.1
IscBind9.12.4P1
IscBind9.9.3S1
IscBind9.10.5S1
IscBind9.10.7S1
IscBind9.11.3S1
IscBind9.11.5S3
IscBind9.11.6S1
IscBind9.11.7S1
IscBind9.11.8S1
DebianDebian Linux8.0
DebianDebian Linux9.0
DebianDebian Linux10.0
FedoraprojectFedora31
FedoraprojectFedora32
OpensuseLeap15.1
OpensuseLeap15.2
CanonicalUbuntu Linux12.04
CanonicalUbuntu Linux14.04
CanonicalUbuntu Linux16.04
CanonicalUbuntu Linux18.04
CanonicalUbuntu Linux19.10
CanonicalUbuntu Linux20.04

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-8617?
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.
How severe is CVE-2020-8617?
CVE-2020-8617 has a CVSS score of 5.9/10 (MEDIUM severity). The EPSS model estimates a 93.42% probability of exploitation in the next 30 days.
How do I fix CVE-2020-8617?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-8617?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST