CyberRota Analysis
AI-GeneratedBIND versions 9.18.0 to 9.18.50, 9.20.0 to 9.20.24, 9.21.0 to 9.21.23, and specific S1 versions may incorrectly validate child-zone NSEC3 records, allowing attackers to forge authenticated NXDOMAIN responses. This vulnerability could lead to DNS spoofing, potentially disrupting services and misleading users. Organizations using affected BIND versions should prioritize patching to mitigate the risk of DNS-related attacks.
Original NVD Description
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge authenticated NXDOMAIN responses. This issue affects BIND 9 versions 9.18.0 through 9.18.50, 9.20.0 through 9.20.24, 9.21.0 through 9.21.23, 9.11.3-S1 through 9.18.50-S1, and 9.20.9-S1 through 9.20.24-S1.