CVE-2015-5477 is a critical denial-of-service vulnerability affecting ISC BIND 9.x versions before 9.9.7-P2 and 9.10.x before 9.10.2-P3, allowing remote attackers to crash the daemon via specially crafted TKEY queries. With a CVSS score of 7.8 and an EPSS score indicating high exploitability, this flaw is easily exploitable over the network with low attack complexity, leading to a complete loss of availability for affected DNS services. Exploit code, including Metasploit modules and ExploitDB proofs-of-concept, is publicly available, and there is evidence of active exploitation and significant community discussion, as highlighted by media coverage and Reddit posts.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.9.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:p1:*:*:*:*:*:* | ||
<= 9.10.2CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:p2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.