CVE-2017-3143 describes an authentication bypass vulnerability in multiple versions of BIND DNS software, including those distributed by Debian and Red Hat. An attacker with knowledge of a valid TSIG key name could manipulate BIND into accepting unauthorized dynamic updates. This medium-severity vulnerability (CVSS 5.9) has a high impact on integrity, requiring high attack complexity but no user interaction. While not actively exploited in the wild and lacking public exploit code, it has garnered some community attention and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.4.0, <= 9.8.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.9.0, <= 9.9.10CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.10.0, <= 9.10.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.11.0, <= 9.11.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.0CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.0:p1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.