Vulnerabilities
Vulnerable Software
Frrouting:  >> Frrouting  >> 8.5.3  Security Vulnerabilities
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes, e.g., one with only an unknown transit attribute.
CVSS Score
5.9
EPSS Score
0.001
Published
2023-10-26
An issue was discovered in FRRouting FRR through 9.0. bgp_nlri_parse_flowspec in bgpd/bgp_flowspec.c processes malformed requests with no attributes, leading to a NULL pointer dereference.
CVSS Score
7.5
EPSS Score
0.001
Published
2023-09-05
FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
CVSS Score
7.5
EPSS Score
0.006
Published
2023-08-29
An issue was discovered in FRRouting FRR 9.0. bgpd/bgp_open.c does not check for an overly large length of the rcv software version.
CVSS Score
9.8
EPSS Score
0.005
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.
CVSS Score
7.5
EPSS Score
0.003
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. There is an out-of-bounds read in bgp_attr_aigp_valid in bgpd/bgp_attr.c because there is no check for the availability of two bytes during AIGP validation.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-08-29
An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c can read the initial byte of the ORF header in an ahead-of-stream situation.
CVSS Score
9.1
EPSS Score
0.002
Published
2023-08-29


Contact Us

Shodan ® - All rights reserved