PatchSiren cyber security CVE debrief
CVE-2023-5680 ISC CVE debrief
A vulnerability in BIND 9 DNS server software can cause the `named` process to crash via assertion failure when DNS64 and serve-stale features are both enabled during recursive resolution. This denial-of-service condition affects multiple BIND 9 version branches and has been identified as affecting Siemens SINEC INS industrial network management software, which incorporates the vulnerable BIND component. The issue was published on November 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH severity).
- Vendor
- ISC
- Product
- SINEC INS
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-12
- Original CVE updated
- 2024-11-12
- Advisory published
- 2024-11-12
- Advisory updated
- 2024-11-12
Who should care
Organizations operating Siemens SINEC INS for industrial network management, DNS infrastructure administrators using BIND 9 recursive resolvers with DNS64 and serve-stale enabled, and critical infrastructure operators dependent on stable DNS resolution services.
Technical summary
The vulnerability stems from an implementation flaw in BIND 9 where the DNS64 (IPv6-to-IPv4 translation) and serve-stale (cache serving of expired records) features interact improperly during recursive DNS resolution. When both features are enabled, the `named` daemon can encounter an assertion failure condition that terminates the process, resulting in denial of service for DNS resolution. Affected BIND 9 versions span the 9.16.12-9.16.45, 9.18.0-9.18.21, and 9.19.0-9.19.19 release branches, plus corresponding S1 (subscription) branches. Siemens SINEC INS, an industrial network management system, incorporates vulnerable BIND 9 components and is specifically called out in CISA advisory ICSA-24-319-08 with a vendor fix available in V1.0 SP2 Update 3.
Defensive priority
HIGH
Recommended defensive actions
- Update Siemens SINEC INS to V1.0 SP2 Update 3 or later version per vendor guidance
- Review BIND 9 configurations for DNS64 and serve-stale feature co-enablement
- Monitor recursive DNS server stability and crash logs for assertion failures
- Apply BIND 9 vendor patches for affected versions 9.16.12-9.16.45, 9.18.0-9.18.21, 9.19.0-9.19.19, and corresponding S1 branches
- Consider disabling DNS64 or serve-stale temporarily if patching is not immediately feasible and the features are not required
Evidence notes
CVE published 2024-11-12. CISA ICS advisory ICSA-24-319-08 confirms Siemens SINEC INS as affected product with vendor fix available. Root cause is interaction between DNS64 and serve-stale features in BIND 9 recursive resolver.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-5680 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-5680
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-5680 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-5680
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-08.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/csaf/ssa-915275.json
Reference
-
Source reference
Unverified legacy reference
URL: https://cert-portal.siemens.com/productcert/html/ssa-915275.html
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-08
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.