CVE-2001-0497
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
21/07/2001
Last modified:
03/04/2025
Description
dnskeygen in BIND 8.2.4 and earlier, and dnssec-keygen in BIND 9.1.2 and earlier, set insecure permissions for a HMAC-MD5 shared secret key file used for DNS Transactional Signatures (TSIG), which allows attackers to obtain the keys and perform dynamic DNS updates.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
4.60
Severity 2.0
MEDIUM
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | 8.2.4 (including) | |
cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* | 9.0 (including) | 9.1.2 (including) |
To consult the complete list of CPE names with products and versions, see this page