Vulnerability Details CVE-2001-0497
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 30.3%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 4.6
Products affected by CVE-2001-0497
-
-
-
-
cpe:2.3:a:isc:bind:4.9.10
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
-
cpe:2.3:a:isc:bind:8.2.3_t1a
-
cpe:2.3:a:isc:bind:8.2.3_t9b
-
-
-
-
-
-
-
-