CVE-2017-3143

HIGH

BIND 9.4.0-9.11.1-P1 - Unauthorized Dynamic Update via TSIG Key Manipulation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-3143. PoCs published by saaph.

AI-analyzed exploit summary This repository contains a proof-of-concept exploit for CVE-2017-3143, a TSIG bypass vulnerability in BIND and Knot DNS. The exploit leverages the dnspython library to craft malicious DNS updates, bypassing TSIG authentication.

Description

An attacker who is able to send and receive messages to an authoritative DNS server and who has knowledge of a valid TSIG key name for the zone and service being targeted may be able to manipulate BIND into accepting an unauthorized dynamic update. Affects BIND 9.4.0->9.8.8, 9.9.0->9.9.10-P1, 9.10.0->9.10.5-P1, 9.11.0->9.11.1-P1, 9.9.3-S1->9.9.10-S2, 9.10.5-S1->9.10.5-S2.

Exploits (1)

nomisec WORKING POC 1 stars
by saaph · poc
https://github.com/saaph/CVE-2017-3143

This repository contains a proof-of-concept exploit for CVE-2017-3143, a TSIG bypass vulnerability in BIND and Knot DNS. The exploit leverages the dnspython library to craft malicious DNS updates, bypassing TSIG authentication.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: BIND 9, Knot DNS
No auth needed
Prerequisites: Network access to vulnerable DNS server · Ability to send crafted DNS packets
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (8)

Core 8
Core References
Vendor Advisory x_refsource_confirm
https://kb.isc.org/docs/aa-01503
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1680
Third Party Advisory vendor-advisory x_refsource_redhat
https://access.redhat.com/errata/RHSA-2017:1679
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038809
Third Party Advisory vendor-advisory x_refsource_debian
https://www.debian.org/security/2017/dsa-3904
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/99337
Vendor Advisory x_refsource_confirm
https://security.netapp.com/advisory/ntap-20190830-0003/

Scores

CVSS v3 7.5
EPSS 0.2693
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Details

Status published
Products (23)
debian/debian_linux 8.0
debian/debian_linux 9.0
isc/bind 9.9.0 p1
isc/bind 9.9.3 s1
isc/bind 9.9.10 s2
isc/bind 9.10.5 p1 (3 CPE variants)
isc/bind 9.11.1 p1
isc/bind 9.4.0 - 9.8.8
redhat/enterprise_linux_desktop 6.0
redhat/enterprise_linux_desktop 7.0
... and 13 more
Published Jan 16, 2019
Tracked Since Feb 18, 2026