CVE-2020-8616

Advisory lineage Upstream: 0 Downstream: 27
Modified
Published: 19 May 2020, 14:05
Last modified:16 Sept 2024, 23:55

Vulnerability Summary

Overall Risk (default)
medium
47/100
CVSS Score
8.6 HIGH
v3.1 (cve.org)
EPSS Score
15.34% MEDIUM
15% probability -4.54%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

19 May 2020, 14:05
Published
Vulnerability first disclosed
16 Sept 2024, 23:55
Last Modified
Vulnerability information updated

Description

A malicious actor who intentionally exploits this lack of effective limitation on the number of fetches performed when processing referrals can, through the use of specially crafted referrals, cause a recursing server to issue a very large number of fetches in an attempt to process the referral. This has at least two potential effects: The performance of the recursing server can potentially be degraded by the additional work required to perform these fetches, and The attacker can exploit this behavior to use the recursing server as a reflector in a reflection attack with a high amplification factor.

CVSS Metrics

  • v3.1HIGHScore: 8.6CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:N/A:H
  • v2.0MEDIUMScore: 5AV:N/AC:L/Au:N/C:N/I:N/A:P

EPSS Trends

Current EPSS score: 15.34% Percentile: 95%

Techniques & Countermeasures

  • CWE-400Uncontrolled Resource Consumption

    The product does not properly control the allocation and maintenance of a limited resource.

Affected Systems

  • debiandebian_linux

    9.0 | 10.0

  • iscbind

    ≥ 9.0.0, ≤ 9.11.18 | ≥ 9.12.0, ≤ 9.12.4 | ≥ 9.13.0, ≤ 9.13.7 | ≥ 9.14.0, ≤ 9.14.11 | ≥ 9.15.0, ≤ 9.15.6 | ≥ 9.16.0, ≤ 9.16.2 | ≥ 9.17.0, ≤ 9.17.1 | 9.12.4:p1 | 9.12.4:p2 | 9.9.3:s1 | 9.10.5:s1 | 9.10.7:s1 | 9.11.3:s1 | 9.11.5:s3 | 9.11.5:s5 | 9.11.6:s1 | 9.11.7:s1 | 9.11.8:s1

  • iscbind9

    9.0.0 -> 9.11.18, 9.12.0 -> 9.12.4-P2, 9.14.0 -> 9.14.11, 9.16.0 -> 9.16.2, and releases 9.17.0 -> 9.17.1 of the 9.17 experimental development branch. All releases in the obsolete 9.13 and 9.15 development branches. All releases of BIND Supported Preview Edition from 9.9.3-S1 -> 9.11.18-S1

References (13)