7.5

CVE-2022-3080

By sending specific queries to the resolver, an attacker can cause named to crash.

Data is provided by the National Vulnerability Database (NVD)
IscBind SwEdition- Version >= 9.16.14 < 9.16.33
IscBind SwEdition- Version >= 9.18.0 < 9.18.7
IscBind SwEdition- Version >= 9.19.0 < 9.19.5
IscBind Version9.16.14 Updates1 SwEditionsupported_preview
IscBind Version9.16.21 Updates1 SwEditionsupported_preview
IscBind Version9.16.32 Updates1 SwEditionsupported_preview
FedoraprojectFedora Version35
FedoraprojectFedora Version36
FedoraprojectFedora Version37
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.1% 0.29
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
security-officer@isc.org 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CWE-613 Insufficient Session Expiration

According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."