CVE-2019-6475 is a high-severity vulnerability affecting BIND versions 9.14.0-9.14.6 and 9.15.0-9.15.4, specifically within its mirror zone feature. An on-path attacker could exploit a flaw in validity checks to replace legitimately validated zone data, such as the root zone, with forged information. This could lead to DNS cache poisoning, with a CVSS score of 7.5 (High) due to its network attack vector and high integrity impact. There is no evidence of active exploitation, public exploit code, or significant community discussion surrounding this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.14.0, <= 9.14.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.15.0, <= 9.15.4CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.