5.3

CVE-2023-38283

Exploit
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
OpenbgpdOpenbgpd Version < 8.1
   OpenbsdOpenbsd Version < 7.3
   OpenbsdOpenbsd Version7.3 Update-
   OpenbsdOpenbsd Version7.3 Updateerrata_001
   OpenbsdOpenbsd Version7.3 Updateerrata_002
   OpenbsdOpenbsd Version7.3 Updateerrata_003
   OpenbsdOpenbsd Version7.3 Updateerrata_004
   OpenbsdOpenbsd Version7.3 Updateerrata_005
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.12% 0.32
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5.3 3.9 1.4
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CWE-754 Improper Check for Unusual or Exceptional Conditions

The product does not check or incorrectly checks for unusual or exceptional conditions that are not expected to occur frequently during day to day operation of the product.