Impact
BIND may accept child‑zone NSEC3 records that do not correctly represent the zone’s existence, allowing an attacker to forge authenticated NXDOMAIN responses. This flaw can be used to deceive clients into believing a domain does not exist or lies elsewhere, enabling redirect or denial of service without needing direct access to the zone data. The weakness is defined by CWE‑345 (Incorrect Validation of Data) and CWE‑347 (Incorrect Logical Comparison).
Affected Systems
ISC BIND 9 is affected, specifically versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3‑S1 through 9.18.50‑S1, and 9.20.9‑S1 through 9.20.24‑S1. All deployments using these releases should be assessed for exposure.
Risk and Exploitability
The CVSS score of 6.8 classifies this as a medium‑severity issue. EPSS is reported as less than 1%, indicating a very low probability of active exploitation at present, and the vulnerability is not listed in CISA's KEV catalog. The likely attack vector is a remote attacker sending specially crafted DNS queries to a vulnerable server; successful exploitation would result in forged authenticated NXDOMAIN responses, potentially redirecting traffic or causing application failures. No workarounds are known, so mitigation relies on updating BIND to a patched release.
OpenCVE Enrichment
Debian DLA
Debian DSA