CVE-2021-25220

BIND 9.11.0 -> 9.11.36 9.12.0 -> 9.16.26 9.17.0 -> 9.18.0 BIND Supported Preview Editions: 9.11.4-S1 -> 9.11.36-S1 9.16.8-S1 -> 9.16.26-S1 Versions of BIND 9 earlier than those shown - back to 9.1.0, including Supported Preview Editions - are also believed to be affected but have not been tested as they are EOL. The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
HTTP Request/Response Smuggling
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
iscCNA
6.8 MEDIUM
NETWORK
LOW
HIGH
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 24%
VendorProductVersion
iscbind
9.11.0 ≤
𝑥
< 9.11.37
iscbind
9.11.4 ≤
𝑥
< 9.11.37
iscbind
9.12.0 ≤
𝑥
< 9.16.27
iscbind
9.16.8 ≤
𝑥
< 9.16.27
iscbind
9.17.0 ≤
𝑥
≤ 9.18.0
netapph300s_firmware
-
netapph500s_firmware
-
netapph700s_firmware
-
netapph300e_firmware
-
netapph500e_firmware
-
netapph700e_firmware
-
netapph410s_firmware
-
netapph410c_firmware
-
siemenssinec_ins
𝑥
< 1.0
siemenssinec_ins
1.0
siemenssinec_ins
1.0:sp1
juniperjunos
𝑥
< 19.3
juniperjunos
19.3
juniperjunos
19.3:r1-s1
juniperjunos
19.3:r2
juniperjunos
19.3:r2-s1
juniperjunos
19.3:r2-s2
juniperjunos
19.3:r2-s3
juniperjunos
19.3:r2-s4
juniperjunos
19.3:r2-s5
juniperjunos
19.3:r2-s6
juniperjunos
19.3:r2-s7
juniperjunos
19.3:r3
juniperjunos
19.3:r3-s1
juniperjunos
19.3:r3-s2
juniperjunos
19.3:r3-s3
juniperjunos
19.3:r3-s4
juniperjunos
19.3:r3-s5
juniperjunos
19.3:r3-s6
juniperjunos
19.4
juniperjunos
19.4:r1
juniperjunos
19.4:r1-s1
juniperjunos
19.4:r1-s2
juniperjunos
19.4:r1-s3
juniperjunos
19.4:r1-s4
juniperjunos
19.4:r2
juniperjunos
19.4:r2-s1
juniperjunos
19.4:r2-s2
juniperjunos
19.4:r2-s3
juniperjunos
19.4:r2-s4
juniperjunos
19.4:r2-s5
juniperjunos
19.4:r2-s6
juniperjunos
19.4:r2-s7
juniperjunos
19.4:r3
juniperjunos
19.4:r3-s1
juniperjunos
19.4:r3-s2
juniperjunos
19.4:r3-s3
juniperjunos
19.4:r3-s4
juniperjunos
19.4:r3-s5
juniperjunos
19.4:r3-s6
juniperjunos
19.4:r3-s7
juniperjunos
19.4:r3-s8
juniperjunos
20.2
juniperjunos
20.2:r1
juniperjunos
20.2:r1-s1
juniperjunos
20.2:r1-s2
juniperjunos
20.2:r1-s3
juniperjunos
20.2:r2
juniperjunos
20.2:r2-s1
juniperjunos
20.2:r2-s2
juniperjunos
20.2:r2-s3
juniperjunos
20.2:r3
juniperjunos
20.2:r3-s1
juniperjunos
20.2:r3-s2
juniperjunos
20.2:r3-s3
juniperjunos
20.2:r3-s4
juniperjunos
20.3
juniperjunos
20.3:r1
juniperjunos
20.3:r1-s1
juniperjunos
20.3:r1-s2
juniperjunos
20.3:r2
juniperjunos
20.3:r2-s1
juniperjunos
20.3:r3
juniperjunos
20.3:r3-s1
juniperjunos
20.3:r3-s2
juniperjunos
20.3:r3-s3
juniperjunos
20.3:r3-s4
juniperjunos
20.4
juniperjunos
20.4:r1
juniperjunos
20.4:r1-s1
juniperjunos
20.4:r2
juniperjunos
20.4:r2-s1
juniperjunos
20.4:r2-s2
juniperjunos
20.4:r3
juniperjunos
20.4:r3-s1
juniperjunos
20.4:r3-s2
juniperjunos
20.4:r3-s3
juniperjunos
20.4:r3-s4
juniperjunos
21.1
juniperjunos
21.1:r1
juniperjunos
21.1:r1-s1
juniperjunos
21.1:r2
juniperjunos
21.1:r2-s1
juniperjunos
21.1:r2-s2
juniperjunos
21.1:r3
juniperjunos
21.1:r3-s1
juniperjunos
21.1:r3-s2
juniperjunos
21.2
juniperjunos
21.2:r1
juniperjunos
21.2:r1-s1
juniperjunos
21.2:r1-s2
juniperjunos
21.2:r2
juniperjunos
21.2:r2-s1
juniperjunos
21.2:r2-s2
juniperjunos
21.2:r3
juniperjunos
21.2:r3-s1
juniperjunos
21.3
juniperjunos
21.3:r1
juniperjunos
21.3:r1-s1
juniperjunos
21.3:r1-s2
juniperjunos
21.3:r2
juniperjunos
21.3:r2-s1
juniperjunos
21.3:r2-s2
juniperjunos
21.3:r3
juniperjunos
21.4
juniperjunos
21.4:r1
juniperjunos
21.4:r1-s1
juniperjunos
21.4:r1-s2
juniperjunos
21.4:r2
juniperjunos
22.1:r1
juniperjunos
22.1:r1-s1
juniperjunos
22.2:r1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
bind9
bullseye
1:9.16.50-1~deb11u2
fixed
bullseye (security)
1:9.16.50-1~deb11u1
fixed
bookworm
1:9.18.28-1~deb12u2
fixed
bookworm (security)
1:9.18.28-1~deb12u2
fixed
sid
1:9.20.2-1
fixed
trixie
1:9.20.2-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
bind9
jammy
Fixed 1:9.18.0-2ubuntu3
released
impish
Fixed 1:9.16.15-1ubuntu1.2
released
focal
Fixed 1:9.16.1-0ubuntu2.10
released
bionic
Fixed 1:9.11.3+dfsg-1ubuntu1.17
released
xenial
Fixed 1:9.10.3.dfsg.P4-8ubuntu1.19+esm2
released
trusty
Fixed 1:9.9.5.dfsg-3ubuntu0.19+esm6
released
References