Vulnerability identifier: #VU17828
Vulnerability risk: Low
CVSSv3.1: 4.6 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:U/RL:O/RC:C]
CVE-ID:
CWE-ID:
CWE-200
Exploitation vector: Network
Exploit availability: No
Vulnerable software:
ISC BIND
Server applications /
DNS servers
Vendor: ISC
Description
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to controls for zone transfers may not be properly applied to Dynamically Loadable Zones (DLZs) if the zones are writable. A remote attacker can request and receive a zone transfer of a DLZ even when not permitted to do so by the allow-transfer ACL.
Mitigation
The vulnerability has been fixed in the versions 9.11.5-P4, 9.12.3-P4.
Vulnerable software versions
ISC BIND: 4.9.9 - 9.13.6
External links
http://kb.isc.org/docs/cve-2019-6465
Can this vulnerability be exploited remotely?
Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.
Is there known malware, which exploits this vulnerability?
No. We are not aware of malware exploiting this vulnerability.