CVE-2022-1183
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (6.03%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
On vulnerable configurations, the named daemon may, in some circumstances, terminate with an assertion failure. Vulnerable configurations are those that include a reference to http within the listen-on statements in their named.conf. TLS is used by both DNS over TLS (DoT) and DNS over HTTPS (DoH), but configurations using DoT alone are unaffected. Affects BIND 9.18.0 -> 9.18.2 and version 9.19.0 of the BIND 9.19 development branch.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 6.03% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-617
- Affected
- isc/bind · netapp/h410c firmware · netapp/h300s firmware · netapp/h500s firmware · netapp/h700s firmware · netapp/h410s firmware
- Source
- security-officer@isc.org
References
- https://kb.isc.org/docs/cve-2022-1183Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220707-0002/Third Party Advisory
- https://kb.isc.org/docs/cve-2022-1183Vendor Advisory
- https://security.netapp.com/advisory/ntap-20220707-0002/Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.