CVE-2015-5477: ISC BIND Data Processing Errors Vulnerability
Summary
ISC BIND has a data processing errors vulnerability (CVE-2015-5477) that could permit remote attackers to cause a denial of service through TKEY queries. Organizations must apply vendor-provided mitigations and adhere to CISA's BOD 26-04 guidance for prioritizing security updates.
IFF Assessment
This vulnerability allows for denial of service attacks, which negatively impacts the availability of services for defenders.
Severity
The CVSS score is estimated to be 7.5 (High) due to the potential for a denial of service (impact) with a remote attack vector and no authentication required.
CISA KEV: Listed as actively exploited. Federal patch due: October 11, 2026. Known ransomware use: Unknown.
Defender Context
This vulnerability in ISC BIND can be exploited remotely to cause denial of service, impacting the availability of DNS services. Defenders should prioritize applying patches or mitigations provided by the vendor to address this issue, especially considering CISA's directive on risk-based patching.