Vulnerability Details CVE-2022-0396
BIND 9.16.11 -> 9.16.26, 9.17.0 -> 9.18.0 and versions 9.16.11-S1 -> 9.16.26-S1 of the BIND Supported Preview Edition. Specifically crafted TCP streams can cause connections to BIND to remain in CLOSE_WAIT status for an indefinite period of time, even after the client has terminated the connection.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.0
EPSS Ranking 0.7%
CVSS Severity
CVSS v3 Score 5.3
CVSS v2 Score 4.3
Products affected by CVE-2022-0396
-
cpe:2.3:a:isc:bind:9.16.11
-
cpe:2.3:a:isc:bind:9.16.12
-
cpe:2.3:a:isc:bind:9.16.13
-
cpe:2.3:a:isc:bind:9.16.14
-
cpe:2.3:a:isc:bind:9.16.15
-
cpe:2.3:a:isc:bind:9.16.19
-
cpe:2.3:a:isc:bind:9.16.21
-
cpe:2.3:a:isc:bind:9.16.22
-
cpe:2.3:a:isc:bind:9.17.0
-
cpe:2.3:a:isc:bind:9.17.1
-
cpe:2.3:a:isc:bind:9.17.10
-
cpe:2.3:a:isc:bind:9.17.11
-
cpe:2.3:a:isc:bind:9.17.12
-
cpe:2.3:a:isc:bind:9.17.16
-
cpe:2.3:a:isc:bind:9.17.18
-
cpe:2.3:a:isc:bind:9.17.19
-
cpe:2.3:a:isc:bind:9.17.2
-
cpe:2.3:a:isc:bind:9.17.20
-
cpe:2.3:a:isc:bind:9.17.21
-
cpe:2.3:a:isc:bind:9.17.22
-
cpe:2.3:a:isc:bind:9.17.3
-
cpe:2.3:a:isc:bind:9.17.4
-
cpe:2.3:a:isc:bind:9.17.5
-
cpe:2.3:a:isc:bind:9.17.6
-
cpe:2.3:a:isc:bind:9.17.7
-
cpe:2.3:a:isc:bind:9.17.8
-
cpe:2.3:a:isc:bind:9.17.9
-
cpe:2.3:a:isc:bind:9.18.0
-
cpe:2.3:a:siemens:sinec_ins:-
-
cpe:2.3:a:siemens:sinec_ins:1.0
-
-
-
-
-
-
-
-
-
cpe:2.3:o:fedoraproject:fedora:34
-
cpe:2.3:o:fedoraproject:fedora:35
-
cpe:2.3:o:fedoraproject:fedora:36
-
cpe:2.3:o:netapp:h300e_firmware:-
-
cpe:2.3:o:netapp:h300s_firmware:-
-
cpe:2.3:o:netapp:h410c_firmware:-
-
cpe:2.3:o:netapp:h410s_firmware:-
-
cpe:2.3:o:netapp:h500e_firmware:-
-
cpe:2.3:o:netapp:h500s_firmware:-
-
cpe:2.3:o:netapp:h700e_firmware:-
-
cpe:2.3:o:netapp:h700s_firmware:-