Impact
A secondary BIND server may accept and apply incremental zone transfer data before the TSIG signature message is received, allowing an attacker without a valid signature to deliver malicious zone contents. The server does not revert to its pre‑transfer state when the final signed packet never arrives, which creates a state where unauthorized records are live in the zone.
Affected Systems
ISC BIND 9 running any of the following editions impacts the vulnerability: versions 9.11.0 through 9.18.50, 9.20.0 through 9.20.27, 9.21.0 through 9.21.25, the corresponding -S1 release lines, and all earlier 9.11.3–9.18.50‑S1 and 9.20.9‑27‑S1 builds.
Risk and Exploitability
The CVSS score of 6.5 indicates a moderate severity, but the EPSS score of less than 1% shows a very low exploitation probability. The vulnerability is not listed in the CISA KEV catalogue. Exploitation requires a multi‑message TCP IXFR transfer against a secondary that trusts TSIG authentication, and the attacker must be able to initiate the transfer. Because the final signature is never verified before the data becomes live, the attack raises the impact to integrity and availability, though it does not provide remote code execution.
OpenCVE Enrichment
Debian DSA