CVE-2022-2795
Status: ModifiedMedium (5.3)—
By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service.
CVSS
- Version: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
- Base score: 5.3
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 2.20%
- Percentile among all scored CVEs: 82
- Score date: 10/6/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
Affected technologies (3)
CWEs
- NVD-CWE-noinfo
References
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-2795
- https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://www.debian.org/security/2022/dsa-5235
- http://www.openwall.com/lists/oss-security/2022/09/21/3
- https://kb.isc.org/docs/cve-2022-2795
- https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/
- https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/
- https://security.gentoo.org/glsa/202210-25
- https://security.netapp.com/advisory/ntap-20241129-0002/
- https://www.debian.org/security/2022/dsa-5235
Raw JSON (NVD)
Show
{
"id": "CVE-2022-2795",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2022-2795",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-04-12T17:20:53.564264Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 5.3,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "LOW",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 1.4,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-officer@isc.org",
"affectedData": [
{
"vendor": "ISC",
"product": "BIND9",
"versions": [
{
"status": "affected",
"version": "Open Source Branches 9.0 through 9.16 9.0.0 through versions before 9.16.33"
},
{
"status": "affected",
"version": "Open Source Branch 9.18 9.18.0 through versions before 9.18.7"
},
{
"status": "affected",
"version": "Supported Preview Branches 9.9-S through 9.11-S 9.9.3-S1 through versions up to and including 9.11.37-S1"
},
{
"status": "affected",
"version": "Supported Preview Branch 9.16-S 9.16.8-S1 through versions before 9.16.33-S1"
},
{
"status": "affected",
"version": "Development Branch 9.19 9.19.0 through versions before 9.19.5"
}
]
}
]
},
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"affectedData": [
{
"cpes": [
"cpe:2.3:a:isc:bind:9.0.0:-:*:*:*:*:*:*"
],
"vendor": "isc",
"product": "bind",
"versions": [
{
"status": "affected",
"version": "9.0.0",
"versionType": "custom",
"lessThanOrEqual": "9.16.32"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:*:*:*"
],
"vendor": "isc",
"product": "bind",
"versions": [
{
"status": "affected",
"version": "9.9.3",
"lessThan": "9.11.37",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:isc:bind:9.16.8:s1:*:*:*:*:*:*"
],
"vendor": "isc",
"product": "bind",
"versions": [
{
"status": "affected",
"version": "9.16.8",
"lessThan": "9.16.32",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
},
{
"cpes": [
"cpe:2.3:a:isc:bind:9.19.0:*:*:*:-:*:*:*"
],
"vendor": "isc",
"product": "bind",
"versions": [
{
"status": "affected",
"version": "9.19.0",
"lessThan": "9.19.4",
"versionType": "custom"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2022-09-21T11:15:09.470",
"references": [
{
"url": "http://www.openwall.com/lists/oss-security/2022/09/21/3",
"tags": [
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://kb.isc.org/docs/cve-2022-2795",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/",
"source": "security-officer@isc.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/",
"source": "security-officer@isc.org"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/",
"source": "security-officer@isc.org"
},
{
"url": "https://security.gentoo.org/glsa/202210-25",
"tags": [
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "https://www.debian.org/security/2022/dsa-5235",
"tags": [
"Third Party Advisory"
],
"source": "security-officer@isc.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2022/09/21/3",
"tags": [
"Mailing List",
"Patch",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://kb.isc.org/docs/cve-2022-2795",
"tags": [
"Patch",
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2022/10/msg00007.html",
"tags": [
"Mailing List",
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/CV4GQWBPF7Y52J2FA24U6UMHQAOXZEF7/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/MRHB6J4Z7BKH4HPEKG5D35QGRD6ANNMT/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/YZJQNUASODNVAWZV6STKG5SD6XIJ446S/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.gentoo.org/glsa/202210-25",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20241129-0002/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.debian.org/security/2022/dsa-5235",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "NVD-CWE-noinfo"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "By flooding the target resolver with queries exploiting this flaw an attacker can significantly impair the resolver's performance, effectively denying legitimate clients access to the DNS resolution service."
},
{
"lang": "es",
"value": "Al inundar el resolvedor de destino con consultas que explotan este fallo, un atacante puede perjudicar significativamente el rendimiento del resolvedor, negando efectivamente a los clientes legítimos el acceso al servicio de resolución DNS"
}
],
"lastModified": "2026-09-01T19:44:42.623",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6CF2AFF8-9D61-442F-98BE-C08FA09C2AD3",
"versionEndExcluding": "9.16.33",
"versionStartIncluding": "9.0.0"
},
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "BAE4B411-40F7-422D-8A5C-775ED1D00189",
"versionEndExcluding": "9.18.7",
"versionStartIncluding": "9.18.0"
},
{
"criteria": "cpe:2.3:a:isc:bind:*:*:*:*:-:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3E1EC206-AC11-4A7E-9723-C4F69FF76892",
"versionEndExcluding": "9.19.5",
"versionStartIncluding": "9.19.0"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.9.3:s1:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FCC182A9-5989-4A87-A3BA-F1CFAEDC95E2"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.9.3:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "40EE014B-0CD8-45F3-BEDB-AE6368A78B04"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.9.12:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "DAF8FA8C-0526-4389-AEC6-92AD62AA3929"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.9.13:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1A9BA952-A5DF-4CBA-8928-0B373C013C32"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.10.5:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CAD41122-C5D8-4256-8CB7-FF88DCD96A13"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.10.7:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6243685F-1E5B-4FF6-AE1B-44798032FBA6"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.3:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C2FE13E1-0646-46FC-875B-CB4C34E20101"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.5:s3:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "62BDFC28-A025-4512-B3D4-AFB4458A87A5"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.5:s3:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1AA16E51-819C-4A1B-B66E-1C60C1782C0D"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.5:s5:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "91533F9F-C0E5-4E84-8A4C-F744F956BF97"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.5:s6:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46E6A4BD-D69B-4A70-821D-5612DD1315EF"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.6:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8AF9D390-0D5B-4963-A2D3-BF1E7CD95E9D"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.7:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AB2B92F1-6BA8-41CA-9000-E0633462CC28"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.8:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "02CA4635-7DFC-408E-A837-856E0F96CA1B"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.12:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3CABCB08-B838-45F7-AA87-77C6B8767DD0"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.14-s1:*:*:*:preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FB597385-BCFD-4CDB-9328-B4F76D586E4D"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.19-s1:*:*:*:preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "42C76CEF-FD0B-40A4-B246-A71F3EC72B29"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.21:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5CC1F26C-4757-4C87-BD8B-2FA456A88C6F"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.27:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "582A4948-B64F-45D4-807A-846A85BB6B42"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.29:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F22E7F6A-0714-480D-ACDF-5027FD6697B2"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.35:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "255AEB06-F071-4433-93E5-9436086C1A6D"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.11.37:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "EF14D712-5FCF-492F-BE3E-745109E9D6E5"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.16.8:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "288EAD80-574B-4839-9C2C-81D6D088A733"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.16.11:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "3595F024-F910-4356-8B5B-D478960FF574"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.16.13:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "94661BA2-27F8-4FFE-B844-9404F735579D"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.16.21:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "751E37C2-8BFD-4306-95C1-8C01CE495FA4"
},
{
"criteria": "cpe:2.3:a:isc:bind:9.16.32:s1:*:*:supported_preview:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC432820-F1A2-4132-A673-2620119553C5"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "07B237A9-69A3-4A9C-9DA0-4E06BD37AE73"
},
{
"criteria": "cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FA6FEEC2-9F11-4643-8827-749718254FED"
}
],
"operator": "OR"
}
]
},
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:35:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80E516C0-98A4-4ADE-B69F-66A772E2BAAA"
},
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:36:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "5C675112-476C-4D7C-BCB9-A2FB2D0BC9FD"
},
{
"criteria": "cpe:2.3:o:fedoraproject:fedora:37:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E30D0E6F-4AE8-4284-8716-991DFA48CC5D"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "security-officer@isc.org"
}