PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-5517 ISC CVE debrief

A vulnerability in BIND 9's query-handling code can cause the `named` DNS server to exit prematurely with an assertion failure. The flaw occurs when `nxdomain-redirect <domain>;` is configured and the resolver receives a PTR query for an RFC 1918 address that would normally result in an authoritative NXDOMAIN response. This denial-of-service condition affects multiple BIND 9 versions and has been identified as affecting Siemens SINEC INS, which incorporates the vulnerable BIND component. The vulnerability is remotely exploitable without authentication, resulting in high availability impact.

Vendor
ISC
Product
SINEC INS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-12
Original CVE updated
2024-11-12
Advisory published
2024-11-12
Advisory updated
2024-11-12

Who should care

Organizations running BIND 9 DNS servers with nxdomain-redirect configured, particularly those with RFC 1918 address space. Industrial operators using Siemens SINEC INS for network management. DNS infrastructure administrators responsible for resolver availability. Security teams monitoring OT/ICS environments where DNS services support critical operations.

Technical summary

The vulnerability resides in BIND 9's query-handling code. When the `nxdomain-redirect` configuration option is enabled, processing a PTR query for an RFC 1918 private address (which would normally generate an authoritative NXDOMAIN response) triggers an assertion failure, causing the `named` process to terminate unexpectedly. This represents a denial-of-service condition for DNS resolution services. The attack vector is network-based, requires no authentication, and is considered low complexity to exploit. Multiple BIND 9 release branches are affected, including stable and development versions. Siemens has confirmed that SINEC INS, an industrial network management product, incorporates the vulnerable BIND component and has issued a vendor fix.

Defensive priority

high

Recommended defensive actions

  • Apply vendor fix: Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version
  • Review DNS server configurations for nxdomain-redirect usage
  • Monitor for unexpected named process terminations
  • Implement network segmentation for DNS infrastructure
  • Apply BIND security updates from ISC if running standalone BIND installations

Evidence notes

CVE published 2024-11-12 per official record. Affects BIND 9 versions 9.12.0 through 9.16.45, 9.18.0 through 9.18.21, 9.19.0 through 9.19.19, and corresponding S1 versions. Siemens SINEC INS affected per CISA CSAF advisory ICSA-24-319-08. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H indicates network-accessible, low-complexity, unauthenticated denial of service.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-5517 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-5517

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-5517 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5517

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.