4.6
CVSSv2

CVE-2001-0497

Published: 21/07/2001 Updated: 08/02/2024
CVSS v2 Base Score: 4.6 | Impact Score: 6.4 | Exploitability Score: 3.9
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

dnskeygen in BIND 8.2.4 and previous versions, and dnssec-keygen in BIND 9.1.2 and previous versions, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows malicious users to obtain the keys and perform dynamic DNS updates.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

isc bind