CVE-2021-25216 is a critical vulnerability affecting BIND 9.x versions configured to use GSS-TSIG features, impacting products from Debian, ISC, NetApp, and Siemens. This flaw allows for a buffer over-read or overflow, leading to denial of service on 64-bit platforms and potential remote code execution on 32-bit platforms. With a CVSS score of 9.8 (Critical) and an EPSS score indicating high exploitability, it presents a significant risk. While there is no known active exploitation or public exploit code, the vulnerability has garnered substantial community discussion and media coverage, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
>= 9.0.0, < 9.11.31CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.12.0, < 9.16.15CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.17.0, < 9.17.12CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2021-25216
May 11, 2021bind: Vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Apr 28, 2021A second vulnerability in BIND's GSSAPI security policy negotiation can be targeted by a buffer overflow attack
Apr 13, 2021