Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2024-0760

27
FAUCET Score

CVE-2024-0760 is a high-severity denial-of-service vulnerability affecting specific versions of BIND 9, where a malicious client can destabilize the server by sending numerous DNS messages over TCP. The attack requires no authentication or user interaction, and while the server may recover, ACLs offer no mitigation. With a CVSS score of 7.5, the vulnerability has a high potential impact on availability. Currently, there is no public exploit code available, nor is it listed on the CISA KEV catalog, though it has garnered some community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
ISCBIND 9
>= 9.18.1, <= 9.18.27, >= 9.18.11-S1, <= 9.18.27-S1, >= 9.19.0, <= 9.19.24CNA affecteddefault unaffected

CVSS Data

CVSS version used by this source: 3.1

7.5HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
4.68%
Probability of exploitation in next 30 days
EPSS Percentile
90.8%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0468 is in the 84th percentile among its peer group of 51,553 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

alistgopatch availablevia llm_extracted
Fixed in: 9.20.4
View patch
microsoftpatch availablevia msrc
Product: 17676-17084Fixed in: 9.20.0-1
microsoftpatch availablevia msrc
Product: 18169-17084Fixed in: 9.20.0-1
microsoftpatch availablevia msrc
Product: azl3 bind 9.20.0-1 on Azure Linux 3.0Fixed in: 9.20.0-1
microsoftpatch availablevia msrc
Product: azl3 bind 9.19.21-1 on Azure Linux 3.0Fixed in: 9.20.0-1
nodejspatch availablevia llm_extracted
View patch
pjsippatch availablevia llm_extracted
View patch
consensysvendor investigatingvia llm_extracted
View patch
nessusvendor investigatingvia llm_extracted
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux 10Fixed in: bind

Vendor Advisories (7)

nodejsllm-nodejs-302528ae26f0d946CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
pjsipllm-pjsip-7ba3ec379210ac70CRITICAL

HP ThinPro 8.1 SP4 Security Updates

Oct 29, 2024
redhatCVE-2024-0760Important

bind: bind9: A flood of DNS messages over TCP may make the server unstable

Jul 23, 2024
microsoft2024-Jul/CVE-2024-0760Important

A flood of DNS messages over TCP may make the server unstable

Jul 9, 2024
nessusllm-nessus-25c7d0d69931d0b7
alistgollm-alistgo-167ff198476a3aed

A flood of DNS messages over TCP may make the server unstable

consensysllm-consensys-0e859b39bc6eb399

References

security.netapp.com / advisory/ntap-20240731-0004
kb.isc.org / docs/cve-2024-0760
openwall.com / lists/oss-security/2024/07/23/1
openwall.com / lists/oss-security/2024/07/31/2