PT-2023-29747 · Ip Infusion · Ip Infusion Zebos

Published

2023-11-21

·

Updated

2023-11-29

·

CVE-2023-45886

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions IP Infusion ZebOS versions 7.10.6 and earlier
Description The issue allows remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. This is related to the BGP daemon (bgpd) in IP Infusion ZebOS.
Recommendations For IP Infusion ZebOS versions 7.10.6 and earlier, consider restricting access to the BGP daemon to minimize the risk of exploitation until a patch is available. As a temporary workaround, network administrators may need to implement additional filtering or validation of BGP update messages to prevent the inclusion of malformed attributes.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2023-45886

Affected Products

Ip Infusion Zebos