Vulnerabilities
Vulnerable Software
Frrouting:  >> Frrouting  Security Vulnerabilities
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-11-03
An issue was discovered in FRRouting FRR through 9.0.1. It mishandles malformed MP_REACH_NLRI data, leading to a crash.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-10-26
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-10-26
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-09-05
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
CVSS Score
7.5
EPSS Score
0.006
Published
2023-08-29
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
CVSS Score
9.8
EPSS Score
0.005
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-08-29
A flaw was found in FRRouting when parsing certain babeld unicast hello messages that are intended to be ignored. This issue may allow an attacker to send specially crafted hello messages with the unicast flag set, the interval field set to 0, or any TLV that contains a sub-TLV with the Mandatory flag set to enter an infinite loop and cause a denial of service.
CVSS Score
3.5
EPSS Score
0.0
Published
2023-07-24


Contact Us

Shodan ® - All rights reserved