Data Injection Vulnerability in BIND Software by ISC
CVE-2025-40778
8.6HIGH
What is CVE-2025-40778?
This vulnerability in BIND software allows attackers to inject malicious data into the cache due to overly lenient acceptance of records from responses. This flaw affects multiple versions of BIND 9, posing a risk of cache poisoning, which could potentially lead to compromised network integrity and confidentiality.
Affected Version(s)
BIND 9 9.11.0 <= 9.16.50
BIND 9 9.18.0 <= 9.18.39
BIND 9 9.20.0 <= 9.20.13
References
CVSS V3.1
Score:
8.6
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed
Timeline
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
Credit
ISC would like to thank Yuxiao Wu, Yunyi Zhang, Baojun Liu, and Haixin Duan from Tsinghua University for bringing this vulnerability to our attention.