5.3
CVE-2023-38283
- EPSS 1.12%
- Veröffentlicht 29.08.2023 16:15:08
- Zuletzt bearbeitet 21.11.2024 08:13:13
- Erkennungen
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Openbgpd ≫ Openbgpd Version < 8.1
Openbsd ≫ Openbsd Version < 7.3
Openbsd ≫ Openbsd Version 7.3 Update -
Openbsd ≫ Openbsd Version 7.3 Update errata_001
Openbsd ≫ Openbsd Version 7.3 Update errata_002
Openbsd ≫ Openbsd Version 7.3 Update errata_003
Openbsd ≫ Openbsd Version 7.3 Update errata_004
Openbsd ≫ Openbsd Version 7.3 Update errata_005
Openbsd ≫ Openbsd Version 7.3 Update -
Openbsd ≫ Openbsd Version 7.3 Update errata_001
Openbsd ≫ Openbsd Version 7.3 Update errata_002
Openbsd ≫ Openbsd Version 7.3 Update errata_003
Openbsd ≫ Openbsd Version 7.3 Update errata_004
Openbsd ≫ Openbsd Version 7.3 Update errata_005
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.12% | 0.619 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.3 | 3.9 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
|
CWE-754 Improper Check for Unusual or Exceptional Conditions
The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.
https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling
https://ftp.openbsd.org/pub/OpenBSD/patches/7.3/common/006_bgpd.patch.sig
https://github.com/openbgpd-portable/openbgpd-portable/releases/tag/8.1
https://news.ycombinator.com/item?id=37305800
https://www.openbsd.org/errata73.html