Impact
The vulnerability arises when ISC BIND 9 accepts a validly signed NSEC3 record from an unrelated sibling zone as formal proof of non‑existence for a queried name, allowing an attacker to forge unsigned DNS answers that bypass the zone’s secure delegation. This flaw is rooted in improper authorization checks (CWE‑290) and misuse of trust references (CWE‑346). The effect is that a resolver may receive an unsolicited response that appears authentic, potentially redirecting client traffic or providing false data.
Affected Systems
The flaw is present in ISC BIND 9 firmware versions 9.11.0 to 9.18.50, 9.20.0 to 9.20.27, 9.21.0 to 9.21.25, and their corresponding patch‑level releases 9.11.3‑S1 to 9.18.50‑S1, 9.20.9‑S1 to 9.20.27‑S1. Any server running these ranges is impacted, and administrators should verify that their BIND installation is not within these version ranges.
Risk and Exploitability
The CVSS score of 5.9 indicates moderate severity, while the EPSS score of less than 1% suggests a very low observed exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and no public exploitation reports exist. An attacker would need to trick a resolver into using a cached NSEC3 RRset; therefore active exploitation is currently unlikely, but mitigations are advisable to protect against potential future abuse.
OpenCVE Enrichment
Debian DSA