CVE-2023-31490Improper Input Validation in Frrouting

Severity
7.5HIGHNVD
OSV7.8OSV5.5
EPSS
5.8%
top 9.51%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 9
Latest updateJun 5

Description

An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages5 packages

Also affects: Debian Linux 10.0, 11.0, 12.0, Fedora 37, 38, 39

🔴Vulnerability Details

4
OSV
frr vulnerabilities2024-06-05
OSV
frr vulnerabilities2023-06-05
GHSA
GHSA-jc82-c2xg-g578: An issue found in Frrouting bgpd v2023-05-09
OSV
CVE-2023-31490: An issue found in Frrouting bgpd v2023-05-09

📋Vendor Advisories

6
Ubuntu
FRR vulnerabilities2024-06-05
Ubuntu
FRR vulnerability2023-08-31
Ubuntu
FRR vulnerabilities2023-06-05
Microsoft
An issue found in Frrouting bgpd v.8.4.2 allows a remote attacker to cause a denial of service via the bgp_attr_psid_sub() function.2023-05-09
Red Hat
frr: missing length check in bgp_attr_psid_sub() can lead do DoS2023-03-24