Infoblox NIOS product is vulnerable to CVE-2021-25220
Summary
Using DNS forwarders can result in incorrect responses being sent to clients.
Overview
On March 16th, 2022 ISC announced a new vulnerability, CVE-2021-25220.
When using forwarders, bogus NS records supplied by, or via, those forwarders may be cached and used by named if it needs to recurse for any reason, causing it to obtain and pass on potentially incorrect answers.
Some examples of configurations that are vulnerable:
Authoritative-only BIND 9 servers are not vulnerable to this flaw.
Please note that this issue is possible if an upstream forwarder has been compromised. If a forwarder is under the same administration, however, a malicious attack of this kind is significantly less probable.
This vulnerability mainly impacts environments where recursive servers point to external forwarders that are not well maintained or are maintained by malicious actors.
Program impacted: BIND
Severity: Medium
Exploitable: Remotely
CVSS Score: 6.8
CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:N/I:H/A:N/E:U/RL:U/RC:C
Affected Versions
8.4.x, 8.5.x (not including 8.5.5), 8.6.x
Impact
The cache could become poisoned with incorrect records leading to queries being made to the wrong servers, which might also result in false information being returned to clients.
Workaround
Modify the configuration to either remove all forwarding or all possibility of recursion.
Resolution
Infoblox suggests following one of the following options to resolve this vulnerability:
File | File Name |
Hotfix Release Form | 8.2.6_CC_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-8-2-6-NIOS-84099-APPLY-464c584608c58c641ba627b3b574b239-Thu-Mar-10-10-52-10-2022.bin2 |
Revert Hotfix | Hotfix-8-2-6-NIOS-84099-REVERT-a041bb9ef12c36f47aca3995d483bc29-Thu-Mar-10-10-51-07-2022.bin2 |
File | File Name |
Hotfix Release Form | 8.4.8_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-8-4-8-NIOS-84100-APPLY-25152a5fd474f08ee8f5b5fc384d70f0-Thu-Mar-10-06-16-21-2022.bin |
Revert Hotfix | Hotfix-8-4-8-NIOS-84100-REVERT-0017a2156b1053e03f749f6d6da5444b-Thu-Mar-10-06-17-22-2022.bin |
File | File Name |
Hotfix Release Form | 8.5.2_CC_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-NIOS-84101-8.5.2-409296-APPLY-f209840f2de567972df1e82c4280fa32-Thu-Mar-10-03-37-25-2022.bin2 |
Revert Hotfix | Hotfix-NIOS-84101-8.5.2-409296-REVERT-ded8e22609880e21a9b28221a08d59d5-Thu-Mar-10-03-38-25-2022.bin2 |
File | File Name |
Hotfix Release Form | 8.5.3_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-8.5.3-417434-NIOS-84102-APPLY-bfe82ed486ef1128b7f101459ce6045b-Thu-Mar-10-10-54-29-2022.bin |
Revert Hotfix | Hotfix-8.5.3-417434-NIOS-84102-REVERT-0b743b67031b640d5f4d32b0256fa2b5-Thu-Mar-10-10-55-30-2022.bin |
File | File Name |
Hotfix Release Form | 8.5.4_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-NIOS-84103-8.5.4-419474-APPLY-a29ee7ffc0e2882d71fcd7c7a67c7e9b-Thu-Mar-10-03-39-29-2022.bin |
Revert Hotfix | Hotfix-NIOS-84103-8.5.4-419474-REVERT-c9c5d66a4a6bb29fdaa05d046e556ec4-Thu-Mar-10-03-40-30-2022.bin |
File | File Name |
Hotfix Release Form | 8.6.1_Hotfix_Release_Form_NIOS-84098.pdf |
Hotfix | Hotfix-8-6-1-NIOS-84105-APPLY-a13965711e22801a3e2ef2fe7d6c6d55-Thu-Mar-10-06-42-07-2022.bin |
Revert Hotfix | Hotfix-8-6-1-NIOS-84105-REVERT-ae656eedbb0f17fd8c6c3951a5ad40b5-Thu-Mar-10-03-48-34-2022.bin |