CVE-2017-15865Sensitive Information Exposure in Frrouting

Severity
7.5HIGHNVD
EPSS
0.5%
top 31.98%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedNov 8
Latest updateMay 17

Description

bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Linux before 3.4.3 and other products, allows remote attackers to obtain sensitive information via a malformed BGP UPDATE packet from a connected peer, which triggers transmission of up to a few thousand unintended bytes because of a mishandled attribute length, aka RN-690 (CM-18492).

CVSS vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:NExploitability: 3.9 | Impact: 3.6

Affected Packages2 packages

NVDfrrouting/frrouting< 2.0.2+2
debiandebian/frr

🔴Vulnerability Details

1
GHSA
GHSA-rh69-rw6w-x274: bgpd in FRRouting (FRR) before 22022-05-17

📋Vendor Advisories

1
Debian
CVE-2017-15865: frr - bgpd in FRRouting (FRR) before 2.0.2 and 3.x before 3.0.2, as used in Cumulus Li...2017