CVE-2022-3080 is a high-severity vulnerability affecting ISC BIND and Fedora Project BIND/Fedora, allowing an unauthenticated attacker to crash the 'named' resolver by sending specific queries. This denial-of-service vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector and low attack complexity, requiring no user interaction. While not listed in CISA's KEV catalog and lacking public exploit code in Metasploit, Nuclei, or ExploitDB, it has garnered significant community discussion and media coverage, indicating awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 9.16.14, < 9.16.33CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.18.0, < 9.18.7CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
>= 9.19.0, < 9.19.5CPE matchmatch criteria | cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:* | ||
9.16.14CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.16.14:s1:*:*:supported_preview:*:*:* | ||
9.16.21CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.16.21:s1:*:*:supported_preview:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
bind: BIND 9 resolvers configured to answer from cache with zero stale-answer-timeout may terminate unexpectedly
Sep 21, 2022BIND 9 resolvers configured to answer from stale cache with zero stale-answer-client-timeout may terminate unexpectedly
Sep 13, 2022BIND 9 resolvers configured to answer from stale cache with zero stale-answer-timeout may terminate unexpectedly