CVE-2020-8616, also known as NXNSAttack, is a critical vulnerability affecting ISC BIND and Debian BIND DNS servers. It allows an attacker to craft malicious DNS referrals, causing a recursing server to issue an excessive number of fetches. This can lead to denial-of-service (DoS) due to degraded server performance and enables high-amplification reflection attacks. With a CVSS score of 8.6 (High), the vulnerability is easily exploitable over the network without user interaction, posing a significant risk for resource exhaustion. While there is no public exploit code available (Metasploit, Nuclei, ExploitDB), the vulnerability has garnered substantial community attention and media coverage, indicating its potential for future exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.0.0, <= 9.11.18CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.12.0, <= 9.12.4CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.13.0, <= 9.13.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.14.0, <= 9.14.11CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | ||
>= 9.15.0, <= 9.15.6CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.