PT-2023-29747 · Ip Infusion · Ip Infusion Zebos
Published
2023-11-21
·
Updated
2023-11-29
·
CVE-2023-45886
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
IP Infusion ZebOS versions 7.10.6 and earlier
Description
The issue allows remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute. This is related to the BGP daemon (bgpd) in IP Infusion ZebOS.
Recommendations
For IP Infusion ZebOS versions 7.10.6 and earlier, consider restricting access to the BGP daemon to minimize the risk of exploitation until a patch is available. As a temporary workaround, network administrators may need to implement additional filtering or validation of BGP update messages to prevent the inclusion of malformed attributes.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ip Infusion Zebos