PT-2023-26344 · Openbsd+1 · Openbgpd+1

Greyface-On

·

Published

2023-08-29

·

Updated

2023-09-07

·

CVE-2023-38283

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions OpenBGPD versions prior to 8.1
Description The issue arises from incorrect handling of BGP update data, specifically the length of path attributes, which can be set by a potentially distant remote actor. This may cause the system to incorrectly reset a session.
Recommendations For OpenBGPD versions prior to 8.1, update to OpenBSD 7.3 errata 006 to resolve the issue.

Exploit

Fix

Improper Check for Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2023-38283

Affected Products

Debian
Openbgpd