Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2018-5378

59
FAUCET Score

CVE-2018-5378 is a medium-severity vulnerability affecting the Quagga BGP daemon (bgpd) prior to version 1.2.3, impacting various Canonical and Debian Linux distributions. This flaw, categorized as a bounds checking error (CWE-119), allows an authenticated attacker to send malformed BGP NOTIFY messages. Successful exploitation could lead to the disclosure of arbitrary data from the bgpd process to a peer and/or a denial-of-service condition due to a crash. While the vulnerability has a CVSS score of 5.9, indicating a medium severity, its attack complexity is high, and there is no evidence of active exploitation, publicly available exploit code, or inclusion in CISA's KEV catalog.

Impacted Technologies

VendorProductVersion(s)CPE
<= 1.2.2CPE matchmatch criteria
cpe:2.3:a:quagga:quagga:*:*:*:*:*:*:*:*
8.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:*
9.0CPE matchmatch criteria
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*
14.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*
16.04CPE matchmatch criteria
cpe:2.3:o:canonical:ubuntu_linux:16.04:*:*:*:lts:*:*:*

CVSS Data

CVSS version used by this source: 3.0

7.1HIGH

CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
LOW
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
4.2
CvssVersion
3.0

Exploit Intelligence

EPSS Score
74.60%
Probability of exploitation in next 30 days
EPSS Percentile
99.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-25
Model: v2026.06.15
This CVE's current EPSS score of 0.7460 is in the 100th percentile among its peer group of 1,424 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Vendor Advisories (1)

redhatCVE-2018-5378Moderate

quagga: bgpd does not properly bounds check the data sent with a NOTIFY allowing leak of sensitive data or crash

Feb 15, 2018

References

savannah.nongnu.org / forum/forum.php
Third Party Advisory
gogs.quagga.net / Quagga/quagga/src/master/doc/security/Quagga-2018-0543.txt
Vendor Advisory
security.gentoo.org / glsa/201804-17
Third Party Advisory
usn.ubuntu.com / 3573-1
Third Party Advisory
debian.org / security/2018/dsa-4115
Third Party Advisory
kb.cert.org / vuls/id/940439
Third Party AdvisoryUS Government Resource