CVE-2013-6230 describes a vulnerability in the Winsock WSAIoctl API within Microsoft Windows Server 2008, specifically impacting ISC BIND versions 9.6-ESV, 9.8, and 9.9. The flaw arises from improper handling of the SIO_GET_INTERFACE_LIST command when processing a 255.255.255.255 netmask, which is misinterpreted as 0.0.0.0. This misinterpretation allows remote attackers to bypass intended IP address restrictions. With a CVSS score of 6.8, this vulnerability is rated as medium severity, indicating a network-based attack with medium complexity that could lead to partial confidentiality, integrity, and availability impacts. The EPSS and FAUCET scores suggest a relatively low likelihood of exploitation in the wild. Currently, there is no evidence of active exploitation, nor is there publicly available exploit code in Metasploit, Nuclei, or ExploitDB. The vulnerability has also received minimal community discussion and media coverage, suggesting a low profile and limited attention from threat actors.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.6:*:*:*:*:*:*:* | ||
9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.6:r5_p1:*:*:*:*:*:* | ||
9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.6:r6_b1:*:*:*:*:*:* | ||
9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.6:r6_rc1:*:*:*:*:*:* | ||
9.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.6:r6_rc2:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.