PatchSiren

PatchSiren cyber security CVE debrief

CVE-2023-5680 ISC CVE debrief

A vulnerability in BIND 9 DNS server software can cause the `named` process to crash via assertion failure when DNS64 and serve-stale features are both enabled during recursive resolution. This denial-of-service condition affects multiple BIND 9 version branches and has been identified as affecting Siemens SINEC INS industrial network management software, which incorporates the vulnerable BIND component. The issue was published on November 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH severity).

Vendor
ISC
Product
SINEC INS
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-12
Original CVE updated
2024-11-12
Advisory published
2024-11-12
Advisory updated
2024-11-12

Who should care

Organizations operating Siemens SINEC INS for industrial network management, DNS infrastructure administrators using BIND 9 recursive resolvers with DNS64 and serve-stale enabled, and critical infrastructure operators dependent on stable DNS resolution services.

Technical summary

The vulnerability stems from an implementation flaw in BIND 9 where the DNS64 (IPv6-to-IPv4 translation) and serve-stale (cache serving of expired records) features interact improperly during recursive DNS resolution. When both features are enabled, the `named` daemon can encounter an assertion failure condition that terminates the process, resulting in denial of service for DNS resolution. Affected BIND 9 versions span the 9.16.12-9.16.45, 9.18.0-9.18.21, and 9.19.0-9.19.19 release branches, plus corresponding S1 (subscription) branches. Siemens SINEC INS, an industrial network management system, incorporates vulnerable BIND 9 components and is specifically called out in CISA advisory ICSA-24-319-08 with a vendor fix available in V1.0 SP2 Update 3.

Defensive priority

HIGH

Recommended defensive actions

  • Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version per vendor guidance
  • Review BIND 9 configurations for DNS64 and serve-stale feature co-enablement
  • Monitor recursive DNS server stability and crash logs for assertion failures
  • Apply BIND 9 vendor patches for affected versions 9.16.12-9.16.45, 9.18.0-9.18.21, 9.19.0-9.19.19, and corresponding S1 branches
  • Consider disabling DNS64 or serve-stale temporarily if patching is not immediately feasible and the features are not required

Evidence notes

CVE published 2024-11-12. CISA ICS advisory ICSA-24-319-08 confirms Siemens SINEC INS as affected product with vendor fix available. Root cause is interaction between DNS64 and serve-stale features in BIND 9 recursive resolver.

Sources and references

Verified primary and authoritative sources

  • CVE-2023-5680 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2023-5680

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2023-5680 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5680

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.