Using a specially-crafted message, an attacker may potentially cause a BIND server to reach an inconsistent state if the attacker knows (or successfully guesses) the name of a TSIG key used by the server. Since BIND, by default, configures a local session key even on servers whose configuration does not otherwise make use of it, almost all current BIND servers are vulnerable. In releases of BIND dating from March 2018 and after, an assertion check in tsig.c detects this inconsistent state and deliberately exits. Prior to the introduction of the check the server would continue operating in an inconsistent state, with potentially harmful results.
Conclusion & alert: CVE-2020-8617 is rated High Exploit Risk (82.8/100): CVSS High severity, with high exploitation likelihood (EPSS 92.63%, 100th percentile). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). EPSS rose +2.89% over the last day, indicating growing attacker interest. Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| 48521 | exploit_db | edb | 2020-05-20 | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-09 | 89.74% | 92.63% | +2.89% |
| 2 | 2026-04-07 | 89.83% | 89.74% | -0.09% |
| 3 | 2026-03-25 | — | 89.83% | — |
Full EPSS history (40 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 5.9 | 3.1 | MEDIUM |
|
2.2 | 3.6 | [email protected] |
| 4.3 | 2.0 | MEDIUM |
|
8.6 | 2.9 | [email protected] |
| vendor | priority | summary | link |
|---|---|---|---|
alpine
|
high | CVE-2020-8617: 1 source package rows (bind); 60 state rows across 10 repos (3.10-main, 3.11-main, 3.12-main, 3.17-main, 3.18-main, 3.19-main, 3.20-main, 3.21-main, 3.22-main, edge-main); fixed 10, open 50. | https://security.alpinelinux.org/vuln/CVE-2020-8617 |
debian
|
not yet assigned | CVE-2020-8617 not yet assigned priority: Debian including 1 source packages (bind9), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. | https://security-tracker.debian.org/tracker/CVE-2020-8617 |
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2020-8617 |
suse
|
high | CVE-2020-8617 severity important: SUSE including 529 source package names (0.1.0:sysuser-shadow-2.0-4.2.8, 0.1.75:sysuser-shadow-2.0-4.2.8, …), 896 product×package rows across 222 product lines (Container bci/bci-init, Container bci/dotnet-aspnet, … (222 product lines)): Fixed 739, Known Affected 157. | https://www.suse.com/security/cve/CVE-2020-8617/ |
ubuntu
|
medium | CVE-2020-8617 medium priority: Ubuntu including 1 source packages (bind9), 6 status rows across 6 suites (bionic, eoan, focal, trusty, upstream, xenial): released 5, needs-triage 1. | https://ubuntu.com/security/CVE-2020-8617 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| isc | bind | >= 9.0.0, <= 9.11.18 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.12.0, <= 9.12.4 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.13.0, <= 9.13.7 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.14.0, <= 9.14.11 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.15.0, <= 9.15.6 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.16.0, <= 9.16.2 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | >= 9.17.0, <= 9.17.1 | cpe:2.3:a:isc:bind:*:*:*:*:*:*:*:* |
| isc | bind | 9.12.4 | cpe:2.3:a:isc:bind:9.12.4:p1:*:*:*:*:*:* |
| isc | bind | 9.12.4 | cpe:2.3:a:isc:bind:9.12.4:p2:*:*:*:*:*:* |
| isc | bind | 9.9.3 | cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.10.5 | cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.10.7 | cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.3 | cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.5 | cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.5 | cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.6 | cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.7 | cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:* |
| isc | bind | 9.11.8 | cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:* |
| debian | debian_linux | 8.0 | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* |
| debian | debian_linux | 9.0 | cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:* |
| debian | debian_linux | 10.0 | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* |
| fedoraproject | fedora | 31 | cpe:2.3:o:fedoraproject:fedora:31:*:*:*:*:*:*:* |
| fedoraproject | fedora | 32 | cpe:2.3:o:fedoraproject:fedora:32:*:*:*:*:*:*:* |
| opensuse | leap | 15.1 | cpe:2.3:o:opensuse:leap:15.1:*:*:*:*:*:*:* |
| opensuse | leap | 15.2 | cpe:2.3:o:opensuse:leap:15.2:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 12.04 | cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:-:*:*:* |
| canonical | ubuntu_linux | 14.04 | cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 16.04 | cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:esm:*:*:* |
| canonical | ubuntu_linux | 18.04 | cpe:2.3:o:canonical:ubuntu_linux:18.04:*:*:*:lts:*:*:* |
| canonical | ubuntu_linux | 19.10 | cpe:2.3:o:canonical:ubuntu_linux:19.10:*:*:*:*:*:*:* |
| canonical | ubuntu_linux | 20.04 | cpe:2.3:o:canonical:ubuntu_linux:20.04:*:*:*:lts:*:*:* |