Related Vulnerabilities: CVE-2017-3143  

An error in TSIG authentication has been found in Bind <= 9.11.1-P1, allowing a remote attacker to bypass authentication in order to perform unauthorized zone updates, altering the content of the zone. The attacker needs to have knowledge of the key name, and should be allowed by the other ACL restrictions if any.

Severity High

Remote Yes

Type Access restriction bypass

Description

An error in TSIG authentication has been found in Bind <= 9.11.1-P1, allowing a remote attacker to bypass authentication in order to perform unauthorized zone updates, altering the content of the zone. The attacker needs to have knowledge of the key name, and should be allowed by the other ACL restrictions if any.

AVG-335 bind 9.11.1.P1-1 9.11.1.P2-1 High Fixed

04 Jul 2017 ASA-201707-3 AVG-335 bind High access restriction bypass

https://kb.isc.org/article/AA-01503/74/CVE-2017-3143%3A-An-error-in-TSIG-authentication-can-permit-unauthorized-dynamic-updates.html