PatchSiren cyber security CVE debrief
CVE-2023-4236 ISC CVE debrief
A vulnerability in BIND 9's DNS-over-TLS implementation can cause the `named` daemon to terminate unexpectedly due to an assertion failure when internal data structures are incorrectly reused under significant query load. This denial-of-service condition affects BIND 9 versions 9.18.0 through 9.18.18 and 9.18.11-S1 through 9.18.18-S1. Siemens SINEC INS, which incorporates affected BIND components, is impacted by this flaw. The vulnerability was published on November 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH severity).
- Vendor
- ISC
- Product
- SINEC INS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations operating Siemens SINEC INS for industrial network management, DNS infrastructure administrators using affected BIND 9 versions with DNS-over-TLS enabled, and OT/ICS security teams responsible for maintaining availability of critical DNS services in industrial environments.
Technical summary
The vulnerability exists in BIND 9's networking code that handles DNS-over-TLS queries. Under conditions of significant DNS-over-TLS query load, internal data structures may be incorrectly reused, triggering an assertion failure that causes the `named` process to terminate unexpectedly. This results in a denial-of-service condition for DNS resolution services. The flaw affects BIND 9 versions 9.18.0 through 9.18.18 and the corresponding S1 (subscription) versions 9.18.11-S1 through 9.18.18-S1. Siemens SINEC INS, an industrial network management product, incorporates affected BIND components and is vulnerable until updated to V1.0 SP2 Update 3 or later.
Defensive priority
HIGH
Recommended defensive actions
- Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version per vendor guidance
- Review DNS-over-TLS query load patterns and implement rate limiting where feasible
- Monitor named process stability and implement process supervision for automatic restart
- Assess network segmentation to limit exposure of DNS services to untrusted networks
- Apply defense-in-depth practices for industrial control systems per CISA guidance
Evidence notes
The vulnerability description and affected version ranges are derived from the CISA CSAF advisory ICSA-24-319-08, which references Siemens security advisory SSA-915275. The CVSS vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H indicates network attack vector with low complexity, no privileges required, and high availability impact.
Official resources
-
CVE-2023-4236 CVE record
CVE.org
-
CVE-2023-4236 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-11-12