6.5

CVE-2021-25214

In BIND 9.8.5 -> 9.8.8, 9.9.3 -> 9.11.29, 9.12.0 -> 9.16.13, and versions BIND 9.9.3-S1 -> 9.11.29-S1 and 9.16.8-S1 -> 9.16.13-S1 of BIND 9 Supported Preview Edition, as well as release versions 9.17.0 -> 9.17.11 of the BIND 9.17 development branch, when a vulnerable version of named receives a malformed IXFR triggering the flaw described above, the named process will terminate due to a failed assertion the next time the transferred secondary zone is refreshed.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IscBind SwEdition- Version >= 9.8.5 <= 9.8.8
IscBind SwEdition- Version >= 9.9.3 < 9.11.31
IscBind SwEdition- Version >= 9.12.0 < 9.16.15
IscBind SwEdition- Version >= 9.17.0 < 9.17.12
IscBind Version9.9.3 Updates1 SwEditionsupported_preview
IscBind Version9.9.12 Updates1 SwEditionsupported_preview
IscBind Version9.9.13 Updates1 SwEditionsupported_preview
IscBind Version9.10.5 Updates1 SwEditionsupported_preview
IscBind Version9.10.7 Updates1 SwEditionsupported_preview
IscBind Version9.11.3 Updates1 SwEditionsupported_preview
IscBind Version9.11.5 Updates3 SwEditionsupported_preview
IscBind Version9.11.5 Updates5 SwEditionsupported_preview
IscBind Version9.11.5 Updates6 SwEditionsupported_preview
IscBind Version9.11.6 Updates1 SwEditionsupported_preview
IscBind Version9.11.7 Updates1 SwEditionsupported_preview
IscBind Version9.11.8 Updates1 SwEditionsupported_preview
IscBind Version9.11.12 Updates1 SwEditionsupported_preview
IscBind Version9.11.21 Updates1 SwEditionsupported_preview
IscBind Version9.11.27 Updates1 SwEditionsupported_preview
IscBind Version9.11.29 Updates1 SwEditionsupported_preview
IscBind Version9.16.8 Updates1 SwEditionsupported_preview
IscBind Version9.16.11 Updates1 SwEditionsupported_preview
IscBind Version9.16.13 Updates1 SwEditionsupported_preview
DebianDebian Linux Version9.0
DebianDebian Linux Version10.0
FedoraprojectFedora Version33
FedoraprojectFedora Version34
NetappActive Iq Unified Manager Version- SwPlatformvsphere
NetappCloud Backup Version-
NetappAff A250 Firmware Version-
   NetappAff A250 Version-
NetappAff 500f Firmware Version-
   NetappAff 500f Version-
NetappH300s Firmware Version-
   NetappH300s Version-
NetappH500s Firmware Version-
   NetappH500s Version-
NetappH700s Firmware Version-
   NetappH700s Version-
NetappH300e Firmware Version-
   NetappH300e Version-
NetappH500e Firmware Version-
   NetappH500e Version-
NetappH700e Firmware Version-
   NetappH700e Version-
NetappH410s Firmware Version-
   NetappH410s Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.71% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvd@nist.gov 4 8 2.9
AV:N/AC:L/Au:S/C:N/I:N/A:P
security-officer@isc.org 6.5 2.8 3.6
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE-617 Reachable Assertion

The product contains an assert() or similar statement that can be triggered by an attacker, which leads to an application exit or other behavior that is more severe than necessary.