CVE-2017-3142 describes an authentication bypass vulnerability in BIND versions 9.4.0 through 9.11.1-P1 and specific S-series releases. An attacker with knowledge of a valid TSIG key name and the ability to send and receive messages to an authoritative DNS server could circumvent TSIG authentication for AXFR requests, potentially leading to unauthorized zone transfers or acceptance of bogus NOTIFY packets. This vulnerability has a CVSS v3.0 score of 3.7 (Low), indicating a network attack vector with high attack complexity and a low impact on confidentiality. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB, although it has received some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4.0, <= 9.8.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.9.0, <= 9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, <= 9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.11.0, <= 9.11.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.0CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.0:p1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.