CVE-2024-11187
It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure. This issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- Puntuación base: 7.5
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 17%
- Percentil entre todas las CVEs puntuadas: 97
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
🎯 Técnicas ATT&CK
Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.
- Explotación
T1190Exploit Public-Facing Applicationinitial access85 % - Impacto principal
T1499.004Application or System Exploitationimpact90 % - Impacto secundario
T1498.002Reflection Amplificationimpact75 %
Vector CVSS AV:N/AC:L/PR:N/UI:N indica explotación remota sin privilegios (T1190). El ataque genera respuestas amplificadas mediante consultas DNS a zonas maliciosas, consumiendo recursos desproporcionados en servidores autoritativos o resolvedores (T1499.004 y T1498.002).
Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.
🛡️ Mitigaciones ATT&CK que cubren estas técnicas
Tecnologías afectadas (1)
⚠ Inferidas por IA a partir de la descripción — NVD aún no ha analizado esta CVE; no son CPE verificados.
CWE
- CWE-405
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2024-11187",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2024-11187",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "yes"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2025-01-30T15:27:46.174106Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.5,
"attackVector": "NETWORK",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "NONE"
},
"impactScore": 3.6,
"exploitabilityScore": 3.9
}
]
},
"affected": [
{
"source": "security-officer@isc.org",
"affectedData": [
{
"vendor": "ISC",
"product": "BIND 9",
"versions": [
{
"status": "affected",
"version": "9.11.0",
"versionType": "custom",
"lessThanOrEqual": "9.11.37"
},
{
"status": "affected",
"version": "9.16.0",
"versionType": "custom",
"lessThanOrEqual": "9.16.50"
},
{
"status": "affected",
"version": "9.18.0",
"versionType": "custom",
"lessThanOrEqual": "9.18.32"
},
{
"status": "affected",
"version": "9.20.0",
"versionType": "custom",
"lessThanOrEqual": "9.20.4"
},
{
"status": "affected",
"version": "9.21.0",
"versionType": "custom",
"lessThanOrEqual": "9.21.3"
},
{
"status": "affected",
"version": "9.11.3-S1",
"versionType": "custom",
"lessThanOrEqual": "9.11.37-S1"
},
{
"status": "affected",
"version": "9.16.8-S1",
"versionType": "custom",
"lessThanOrEqual": "9.16.50-S1"
},
{
"status": "affected",
"version": "9.18.11-S1",
"versionType": "custom",
"lessThanOrEqual": "9.18.32-S1"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2025-01-29T22:15:28.637",
"references": [
{
"url": "https://kb.isc.org/docs/cve-2024-11187",
"source": "security-officer@isc.org"
},
{
"url": "https://lists.debian.org/debian-lts-announce/2025/02/msg00011.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security.netapp.com/advisory/ntap-20250207-0002/",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Deferred",
"weaknesses": [
{
"type": "Secondary",
"source": "security-officer@isc.org",
"description": [
{
"lang": "en",
"value": "CWE-405"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "It is possible to construct a zone such that some queries to it will generate responses containing numerous records in the Additional section. An attacker sending many such queries can cause either the authoritative server itself or an independent resolver to use disproportionate resources processing the queries. Zones will usually need to have been deliberately crafted to attack this exposure.\nThis issue affects BIND 9 versions 9.11.0 through 9.11.37, 9.16.0 through 9.16.50, 9.18.0 through 9.18.32, 9.20.0 through 9.20.4, 9.21.0 through 9.21.3, 9.11.3-S1 through 9.11.37-S1, 9.16.8-S1 through 9.16.50-S1, and 9.18.11-S1 through 9.18.32-S1."
},
{
"lang": "es",
"value": "Es posible construir una zona de manera que algunas consultas generen respuestas que contengan numerosos registros en la sección Adicional. Un atacante que envíe muchas consultas de este tipo puede provocar que el servidor autorizado o un solucionador independiente utilicen recursos desproporcionados para procesar las consultas. Por lo general, será necesario que las zonas hayan sido deliberadamente manipulado para atacar esta exposición. Este problema afecta a las versiones de BIND 9 9.11.0 a 9.11.37, 9.16.0 a 9.16.50, 9.18.0 a 9.18.32, 9.20.0 a 9.20.4, 9.21.0 a 9.21.3, 9.11.3-S1 a 9.11.37-S1, 9.16.8-S1 a 9.16.50-S1 y 9.18.11-S1 a 9.18.32-S1."
}
],
"lastModified": "2026-06-17T06:57:14.430",
"sourceIdentifier": "security-officer@isc.org"
}