Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2007-2930

23
FAUCET Score

CVE-2007-2930 describes a vulnerability in ISC BIND 8 (versions prior to 8.4.7-P1) where the NSID_SHUFFLE_ONLY and NSID_USE_POOL PRNG algorithms generate predictable DNS query identifiers. This flaw allows remote attackers to poison DNS caches, specifically when BIND acts as a resolver sending outgoing queries like NOTIFY messages. The vulnerability has a CVSS score of 4.3, indicating a medium severity with network access required and medium attack complexity, leading to potential data integrity impact (cache poisoning). While not actively exploited in the wild, exploit code is publicly available through ExploitDB, though there is no recorded community discussion or media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
<= 8.4.7CPE matchmatch criteria
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

4.3MEDIUM

AV:N/AC:M/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
NETWORK
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
8.6
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
7.58%
Probability of exploitation in next 30 days
EPSS Percentile
93.9%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-30535 · Aug 27, 2007
This CVE's current EPSS score of 0.0759 is in the 93rd percentile among its peer group of 19,956 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2007-2930

CVE-2007-2930

References

h20000.www2.hp.com / bizsupport/TechSupport/Document.jsp
secunia.com / advisories/26629
secunia.com / advisories/26858
secunia.com / advisories/27433
secunia.com / advisories/27459
secunia.com / advisories/27465
secunia.com / advisories/27696
oval.cisecurity.org / repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A2154
sunsolve.sun.com / search/document.do
sunsolve.sun.com / search/document.do
support.avaya.com / elmodocs2/security/ASA-2007-448.htm
support.nortel.com / go/main.jsp
www116.nortel.com / pub/repository/CLARIFY/DOCUMENT/2007/43/022954-01.pdf
www14.software.ibm.com / webapp/set2/subscriptions/pqvcmjd
ciac.org / ciac/bulletins/r-333.shtml
Patch
isc.org / index.pl
Patch
kb.cert.org / vuls/id/927905
PatchUS Government Resource
securityfocus.com / archive/1/477870/100/100/threaded
securityfocus.com / archive/1/481424/100/0/threaded
securityfocus.com / archive/1/481659/100/0/threaded
securityfocus.com / bid/25459
securitytracker.com / id
trusteer.com / docs/bind8dns.html
vupen.com / english/advisories/2007/2991
vupen.com / english/advisories/2007/3192
vupen.com / english/advisories/2007/3639
vupen.com / english/advisories/2007/3668
vupen.com / english/advisories/2007/3936