CVE-2025-40780

HIGH

BIND <9.21 - Info Disclosure

Title source: llm
STIX 2.1

Description

In specific circumstances, due to a weakness in the Pseudo Random Number Generator (PRNG) that is used, it is possible for an attacker to predict the source port and query ID that BIND will use. This issue affects BIND 9 versions 9.16.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.16.8-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, and 9.20.9-S1 through 9.20.13-S1.

References (2)

Core 2
Core References
Various Sources vendor-advisory
https://kb.isc.org/docs/cve-2025-40780

Scores

CVSS v3 8.6
EPSS 0.0003
EPSS Percentile 7.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-341
Status published
Products (7)
ISC/BIND 9 9.16.0 - 9.16.50
ISC/BIND 9 9.16.8-S1 - 9.16.50-S1
ISC/BIND 9 9.18.0 - 9.18.39
ISC/BIND 9 9.18.11-S1 - 9.18.39-S1
ISC/BIND 9 9.20.0 - 9.20.13
ISC/BIND 9 9.20.9-S1 - 9.20.13-S1
ISC/BIND 9 9.21.0 - 9.21.12
Published Oct 22, 2025
Tracked Since Feb 18, 2026