CVE-2020-8617
Last modified
CVE-2020-8617 is a medium-severity vulnerability rated 5.9/10 on the CVSS scale. Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. EPSS estimates a 93.42% chance of exploitation in the next 30 days.
Description
Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Isc | Bind | >= 9.0.0, <= 9.11.18 | — |
| Isc | Bind | >= 9.12.0, <= 9.12.4 | — |
| Isc | Bind | >= 9.13.0, <= 9.13.7 | — |
| Isc | Bind | >= 9.14.0, <= 9.14.11 | — |
| Isc | Bind | >= 9.15.0, <= 9.15.6 | — |
| Isc | Bind | >= 9.16.0, <= 9.16.2 | — |
| Isc | Bind | >= 9.17.0, <= 9.17.1 | — |
| Isc | Bind | 9.12.4 | P1 |
| Isc | Bind | 9.9.3 | S1 |
| Isc | Bind | 9.10.5 | S1 |
| Isc | Bind | 9.10.7 | S1 |
| Isc | Bind | 9.11.3 | S1 |
| Isc | Bind | 9.11.5 | S3 |
| Isc | Bind | 9.11.6 | S1 |
| Isc | Bind | 9.11.7 | S1 |
| Isc | Bind | 9.11.8 | S1 |
| Debian | Debian Linux | 8.0 | — |
| Debian | Debian Linux | 9.0 | — |
| Debian | Debian Linux | 10.0 | — |
| Fedoraproject | Fedora | 31 | — |
| Fedoraproject | Fedora | 32 | — |
| Opensuse | Leap | 15.1 | — |
| Opensuse | Leap | 15.2 | — |
| Canonical | Ubuntu Linux | 12.04 | — |
| Canonical | Ubuntu Linux | 14.04 | — |
| Canonical | Ubuntu Linux | 16.04 | — |
| Canonical | Ubuntu Linux | 18.04 | — |
| Canonical | Ubuntu Linux | 19.10 | — |
| Canonical | Ubuntu Linux | 20.04 | — |
References
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157836/BIND-TSIG-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2020/05/19/4Mailing List, Patch, Third Party Advisory
- https://kb.isc.org/docs/cve-2020-8617Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00031.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200522-0002/Third Party Advisory
- https://usn.ubuntu.com/4365-1/Third Party Advisory
- https://usn.ubuntu.com/4365-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4689Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00041.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2020-10/msg00044.htmlMailing List, Third Party Advisory
- http://packetstormsecurity.com/files/157836/BIND-TSIG-Denial-Of-Service.htmlThird Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2020/05/19/4Mailing List, Patch, Third Party Advisory
- https://kb.isc.org/docs/cve-2020-8617Patch, Vendor Advisory
- https://lists.debian.org/debian-lts-announce/2020/05/msg00031.htmlMailing List, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20200522-0002/Third Party Advisory
- https://usn.ubuntu.com/4365-1/Third Party Advisory
- https://usn.ubuntu.com/4365-2/Third Party Advisory
- https://www.debian.org/security/2020/dsa-4689Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-8617?
How severe is CVE-2020-8617?
How do I fix CVE-2020-8617?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8608In libslirp 4.1.0, as used in QEMU 4.2.0, tcp_subr.c misuses…5.6
- CVE-2020-8611In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.…8.8
- CVE-2020-8612In Progress MOVEit Transfer 2019.1 before 2019.1.4 and 2019.…9
- CVE-2020-8614An issue was discovered on Askey AP4000W TDC_V1.01.003 devic…9.8
- CVE-2020-8615A CSRF vulnerability in the Tutor LMS plugin before 1.5.3 fo…6.5
- CVE-2020-8616A malicious actor who intentionally exploits this lack of ef…8.6
- CVE-2020-8618An attacker who is permitted to send zone data to a server v…4.9
- CVE-2020-8619In ISC BIND9 versions BIND 9.11.14 -> 9.11.19, BIND 9.14.9 -…4.9
- CVE-2020-8620In BIND 9.15.6 -> 9.16.5, 9.17.0 -> 9.17.3, An attacker who …7.5
- CVE-2020-8621In BIND 9.14.0 -> 9.16.5, 9.17.0 -> 9.17.3, If a server is c…7.5
- CVE-2020-8622In BIND 9.0.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.3…6.5
- CVE-2020-8623In BIND 9.10.0 -> 9.11.21, 9.12.0 -> 9.16.5, 9.17.0 -> 9.17.…7.5
Are you affected by CVE-2020-8617?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
