PatchSiren cyber security CVE debrief
CVE-2023-5517 ISC CVE debrief
A vulnerability in BIND 9's query-handling code can cause the `named` DNS server to exit prematurely with an assertion failure. The flaw occurs when `nxdomain-redirect <domain>;` is configured and the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This denial-of-service condition affects multiple BIND 9 versions and has been identified as affecting Siemens SINEC INS, which incorporates the vulnerable BIND component. The vulnerability is remotely exploitable without authentication, resulting in high availability impact.
- Vendor
- ISC
- Product
- SINEC INS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations running BIND 9 DNS servers with nxdomain-redirect configured, particularly those with RFC 1918 address space. Industrial operators using Siemens SINEC INS for network management. DNS infrastructure administrators responsible for resolver availability. Security teams monitoring OT/ICS environments where DNS services support critical operations.
Technical summary
The vulnerability resides in BIND 9's query-handling code. When the `nxdomain-redirect` configuration option is enabled, processing a PTR query for an RFC 1918 private address (which would normally generate an authoritative NXDOMAIN response) triggers an assertion failure, causing the `named` process to terminate unexpectedly. This represents a denial-of-service condition for DNS resolution services. The attack vector is network-based, requires no authentication, and is considered low complexity to exploit. Multiple BIND 9 release branches are affected, including stable and development versions. Siemens has confirmed that SINEC INS, an industrial network management product, incorporates the vulnerable BIND component and has issued a vendor fix.
Defensive priority
high
Recommended defensive actions
- Apply vendor fix: Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version
- Review DNS server configurations for nxdomain-redirect usage
- Monitor for unexpected named process terminations
- Implement network segmentation for DNS infrastructure
- Apply BIND security updates from ISC if running standalone BIND installations
Evidence notes
CVE published 2024-11-12 per official record. Affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, and corresponding S1 versions. Siemens SINEC INS affected per CISA CSAF advisory ICSA-24-319-08. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H indicates network-accessible, low-complexity, unauthenticated denial of service.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-5517 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-5517
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-5517 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5517
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.