CVE-2018-5736 is a medium-severity assertion failure vulnerability in BIND versions 9.12.0 and 9.12.1, impacting ISC BIND and NetApp products. An authenticated attacker can trigger this flaw by rapidly initiating zone transfers, causing the named process to crash and resulting in a denial of service. The attack complexity is high, but it can be exploited remotely. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.12.0CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.12.0:*:*:*:*:*:*:* | ||
9.12.1CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.12.1:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:netapp:data_ontap_edge:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.