CVE-2018-5745 is a denial-of-service vulnerability affecting multiple versions of ISC BIND, specifically within its "managed-keys" feature. An assertion failure can occur, causing the BIND server to exit, if a trust anchor's keys are replaced with an unsupported algorithm during a key rollover. With a CVSS score of 4.9 (Medium), this vulnerability requires high privileges (PR:H) to exploit over the network (AV:N), resulting in high availability impact (A:H) but no confidentiality or integrity impact. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or KEV entry, and community discussion is minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.9.0, <= 9.10.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.11.0, <= 9.11.4CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.12.0, <= 9.12.2CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.13.0, <= 9.13.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
9.9.3CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:supported_preview:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.