CVE-2017-3143
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 18.3%, higher than 97% of all known CVEs. Patch or mitigate before the next change window.
Description
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
- CVSS 3.0
- 5.9 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
- EPSS
- 18.30% probability · 97th percentile
- CISA KEV
- Not listed
- Affected
- isc/bind · redhat/enterprise linux desktop · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server eus · redhat/enterprise linux server tus · redhat/enterprise linux workstation · debian/debian linux
- Source
- security-officer@isc.org
References
- http://www.securityfocus.com/bid/99337Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038809Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1679Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1680Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_usThird Party Advisory
- https://kb.isc.org/docs/aa-01503Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190830-0003/
- https://www.debian.org/security/2017/dsa-3904Third Party Advisory
- http://www.securityfocus.com/bid/99337Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1038809Third Party Advisory, VDB Entry
- https://access.redhat.com/errata/RHSA-2017:1679Third Party Advisory
- https://access.redhat.com/errata/RHSA-2017:1680Third Party Advisory
- https://h20566.www2.hpe.com/hpsc/doc/public/display?docLocale=en_US&docId=emr_na-hpesbux03772en_usThird Party Advisory
- https://kb.isc.org/docs/aa-01503Vendor Advisory
- https://security.netapp.com/advisory/ntap-20190830-0003/
- https://www.debian.org/security/2017/dsa-3904Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.