Vulnerability record · CVE-2006-0987 · published 3 March 2006
CVE-2006-0987: ISC BIND caching resolver allows open recursion and traffic amplification
Isc · Bind
The default configuration of ISC BIND before 9.4.1-P1, when running as a caching name server, answers recursive queries from arbitrary IP addresses and returns extra delegation information. This makes the server usable as an amplifier in spoofed-source DNS floods, degrading availability for the resolver and its network.
Description
The default configuration of ISC BIND before 9.4.1-P1, when configured as a caching name server, allows recursive queries and provides additional delegation information to arbitrary IP addresses, which allows remote attackers to cause a denial of service (traffic amplification) via DNS queries with spoofed source IP addresses.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityAvailability-only impact with no authentication needed, but exploitation is limited to traffic amplification and the record shows no confirmed in-the-wild use.
What it is
The default configuration of ISC BIND before 9.4.1-P1, when running as a caching name server, answers recursive queries from arbitrary IP addresses and returns extra delegation information. This makes the server usable as an amplifier in spoofed-source DNS floods, degrading availability for the resolver and its network.
Impact
A remote attacker can direct amplified DNS response traffic at a spoofed victim address, causing a denial of service through traffic amplification. No data confidentiality or integrity loss is described; the CVSS impact is availability-only.
Attack surface
Reachable over the network via DNS queries to the caching resolver; no authentication and no user interaction are required (AV:N/AC:L/Au:N). The flaw is a default configuration issue, so any exposed caching resolver with recursion open to arbitrary addresses is affected.
Exploitation
Not listed in CISA KEV and no exploit tags appear in the references, but EPSS is high (0.58033 probability, 99.046 percentile), indicating elevated predicted exploitation activity. The record does not state whether public exploit code exists.
What to do
- Upgrade to ISC BIND 9.4.1-P1 or later, or apply the vendor patch referenced in the US-CERT advisory.
- Restrict recursion to trusted clients using allow-recursion or allow-query ACLs so the resolver does not answer arbitrary IP addresses.
- Disable recursion entirely on name servers that are not intended to be caching resolvers.
- Apply response rate limiting (RRL) to cap amplification volume from the resolver.
- Block or filter outbound DNS responses from resolvers to prevent them being used as reflectors.
Detection
- Monitor resolver query logs for high volumes of recursive queries from many distinct source addresses.
- Alert on large DNS response sizes relative to query sizes, a signature of amplification.
- Track outbound DNS traffic spikes from caching resolvers toward unexpected destinations.
- Audit BIND configuration for missing allow-recursion or allow-query restrictions on internet-facing resolvers.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2006-0987 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2006-0987), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.