CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-40778: BIND 9 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1…

CVE-2025-40778. CVSS 3.1 base score 8.6 (HIGH, Vendor/CNA). EPSS 0.00667 (percentile 0.50247), scored 2026-10-06.

Affected technology

BIND 9 · 9.11.0 through 9.16.50, 9.18.0 through 9.18.39, 9.20.0 through 9.20.13, 9.21.0 through 9.21.12, 9.11.3-S1 through 9.16.50-S1, 9.18.11-S1 through 9.18.39-S1, 9.20.9-S1 through 9.20.13-S1
ISC

Component: Not specified by the source

Attack conditions (Vendor/CNA, CVSS 3.1): Network (remote) · No privileges required · No user interaction required

What an attacker can do

The source says under certain circumstances, BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache. Vendor/CNA’s CVSS 3.1 assessment (base score 8.6/10) rates confidentiality and availability impact as none; integrity impact as high.

Published

CWE
CWE-349
CCR priority
34.6 /100 (P4)
CVSS 3.1
8.6 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N · Vendor/CNA
EPSS
0.00667 · percentile 0.50354 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-40778.html