CVE-2022-0635 is a high-severity denial-of-service vulnerability affecting BIND versions 9.18.0, specifically impacting products from ISC and NetApp. An unauthenticated attacker can remotely trigger a failed assertion check in the named process by sending a specific series of queries, leading to the termination of the BIND service. With a CVSS score of 7.5, this vulnerability is easily exploitable over the network with low attack complexity, resulting in a complete loss of availability. While there is no known active exploitation or public exploit code, the vulnerability has garnered some community discussion and media coverage, indicating awareness within the cybersecurity community.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.18.0CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.18.0:*:*:*:-:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300e_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.