PT-2023-5089 · Pica8+10 · Pica8 Picos+10
Greyface-On
·
Publicado
2023-08-28
·
Atualizado
2024-11-28
·
CVE-2023-38802
CVSS v2.0
7.8
Alta
| Vetor | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FRRouting FRR versions 7.5.1 through 9.0
Pica8 PICOS version 4.3.3.2
PAN-OS (affected versions not specified)
Description
The issue is related to errors in processing input data, allowing a remote attacker to cause a denial of service by sending specially crafted BGP update data. This can be achieved via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation). The denial-of-service impact on the network depends on the network's architecture and fault-tolerant design.
Recommendations
For FRRouting FRR versions 7.5.1 through 9.0, consider disabling the BGP routing feature until a patch is available.
For Pica8 PICOS version 4.3.3.2, restrict access to the BGP update feature to minimize the risk of exploitation.
For PAN-OS, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Alt Linux
Almalinux
Centos
Frrouting Frr
Linuxmint
Pan-Os
Pica8 Picos
Red Hat
Red Os
Suse
Ubuntu