CVE-2017-3143
HIGHBIND 9.4.0-9.11.1-P1 - Unauthorized Dynamic Update via TSIG Key Manipulation
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2017-3143. PoCs published by saaph.
AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2017-3143, a TSIG bypass vulnerability in BIND and Knot DNS. The exploit leverages the dnspython library to craft malicious DNS updates, bypassing TSIG authentication.
Description
An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.
Exploits (1)
This repository contains a proof-of-concept exploit for CVE-2017-3143, a TSIG bypass vulnerability in BIND and Knot DNS. The exploit leverages the dnspython library to craft malicious DNS updates, bypassing TSIG authentication.
References (8)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N