CVE-2020-8623 is a high-severity denial-of-service vulnerability affecting multiple versions of ISC BIND, including those from Canonical, Debian, Fedora, NetApp, OpenSUSE, and Synology. An unauthenticated attacker can crash a vulnerable BIND server by sending a specially crafted query packet, provided the server was built with "--enable-native-pkcs11" and is signing zones with an RSA key. The CVSS score is 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) or significant community discussion has been observed.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.10.0, <= 9.11.21CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.12.1, <= 9.16.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.17.0, <= 9.17.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:* | ||
9.11.21CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.