-
Infoblox NIOS and BloxOne Products are not vulnerable to CVE-2022-0667
Mar 16, 2022•Knowledge Summary: On March 16th, 2022 ISC announced a new security issue encountered in BIND 9.18.0 as CVE-2022-0667. Overview: We refactored the RFC 8198 Aggressive Use of DNSSEC-Validated Cache feature (synth-from-dnssec) for the new BIND 9.18.0 stable release, and changed the default so that is now…
-
Infoblox NIOS and BloxOne products are not vulnerable to CVE-2022-0635
Mar 16, 2022•Knowledge Summary Infoblox NIOS and BloxOne products are not vulnerable to CVE-2022-0635. Overview On March 16th, 2022 ISC announced a new vulnerability, CVE-2022-0635. This issue causes named to terminate unexpectedly. Although the crash cannot be triggered with a single query, repeated patterns of specific…
-
Infoblox NIOS products not vulnerable to CVE-2022-0396
Mar 16, 2022•Knowledge Summary: On March 16, 2022 ISC announced a new security issue encountered in BIND 9.18.0 as CVE-2022-0396. Overview: ISC recently discovered an issue in BIND that allows TCP connection slots to be consumed for an indefinite time frame via a specifically crafted TCP stream sent from a client. This…
-
Infoblox NIOS product is vulnerable to CVE-2021-25220
Infoblox NIOS product is vulnerable to CVE-2021-25220 Mar 17, 2022•Knowledge Summary Using DNS forwarders can result in incorrect responses being sent to clients. Overview On March 16th, 2022 ISC announced a new vulnerability, CVE-2021-25220. When using forwarders, bogus NS records supplied by, or via, those forwarders may…
-
End-Of-Life – NIOS 8.4
Jan 4, 2022•Knowledge End-Of-Life – NIOS 8.4 60 Day ALERT!! NIOS 8.4 will reach end of life as of 2nd March 2022. We recognize the needs of our customers in keeping their critical business operations up and running. We are making this announcement to alert you to plan for migration to our current supported 8.x release…
-
Infoblox NIOS and BloxOne products not vulnerable to CVE-2021-44228
Jan 7, 2021•Knowledge Summary: Recently, a critical vulnerability related to Log4j was identified under CVE-2021-44228. This vulnerability allows attackers to send and execute code remotely. Additional Log4j vulnerabilities have since been identified: CVE-2017-5645, CVE-2019-17571, CVE-2020-9488, CVE-2021-4104,…
-
End-Of-Life – NIOS 8.4
Dec 2, 2021 • 90 Day ALERT!! NIOS 8.4 will reach end of life as of 2nd March 2022. We recognize the needs of our customers in keeping their critical business operations up and running. We are making this announcement to alert you to plan for migration to our current supported 8.x release prior to the EOL date. Should you…
-
Infoblox NIOS is vulnerable to CVE-2021-25219
Oct 27, 2021•Knowledge Summary: Infoblox NIOS is vulnerable to CVE-2021-25219. Overview and Impact: On October 20, 2021 ISC announced CVE-2021-25219 where the lame cache feature of BIND can be abused by an attacker, causing performance degradation on recursive resolvers. The purpose of a resolver’s lame cache is to ensure…
-
Infoblox NIOS and BloxOne products are not vulnerable to CVE-2021-38647
Summary: Sept. 23, 2021 • Infoblox NIOS VMs are not vulnerable to CVE-2021-38647. Overview and Impact: On September 14, 2021 Microsoft Corporation announced CVE-2021-38647 Security Vulnerability referring to the Open Management Infrastructure (OMI) agent tools. This tool is not able to be installed on many vendor’s virtual…
-
NIOS is Vulnerable to CVE-2020-8622, but NOT to CVE-2020-8620, CVE-2020-8621, CVE-2020-8623 & CVE-20
SummaryInfoblox is not vulnerable to the below issues related to BIND: * CVE-2020-8620 * CVE-2020-8621 * CVE-2020-8623 * CVE-2020-8624 Infoblox is vulnerable to the below issues related to BIND: * CVE-2020-8622 OverviewOn August 20, 2020, ISC announced CVE-2020-8620NIOS is not vulnerable to this. This vulnerability is only…