CVE-2022-3488 is a high-severity denial-of-service vulnerability affecting specific versions of BIND 9 (9.11.4-S1 through 9.11.37-S1 and 9.16.8-S1 through 9.16.36-S1). This flaw allows an attacker to trigger an assertion failure, causing BIND to crash, by sending repeated, malformed responses to the same query, particularly when both responses contain ECS pseudo-options and the first is "broken" (e.g., a query/answer name mismatch). The vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low attack complexity and without user interaction, leading to a complete loss of availability. While no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, and it is not listed in CISA's KEV catalog, it has garnered some community attention and media coverage, including an article from SecurityWeek. The EPSS score is relatively low, suggesting a lower likelihood of exploitation compared to many other CVEs.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
9.11.4CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.11.4:s1:*:*:supported_preview:*:*:* | ||
9.11.37CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.11.37:s1:*:*:supported_preview:*:*:* | ||
9.16.8CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:* | ||
9.16.36CPE matchmatch criteria | cpe:2.3:a:isc:bind:9.16.36:s1:*:*:supported_preview:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
bind: processing specially crafted responses in quick succession may lead to assertion failure
Jan 25, 2023BIND Supported Preview Edition named may terminate unexpectedly when processing ECS options in repeated responses to iterative queries