CVE-2023-38802 is a denial-of-service vulnerability affecting FRRouting FRR versions 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2. A remote attacker can exploit this flaw by sending a specially crafted BGP update containing a corrupted Tunnel Encapsulation attribute. With a CVSS score of 7.5 (High), this vulnerability requires no user interaction and has a high impact on availability, potentially leading to prolonged internet outages. While there is no evidence of active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), it has garnered some community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 7.5.1, <= 9.0CPE matchmatch criteria | cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:* | ||
4.3.3.2CPE matchmatch criteria | cpe:2.3:o:pica8:picos:4.3.3.2:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* | ||
12.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:12.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-38802
Sep 12, 2023frr: Incorrect handling of a error in parsing of an invalid section of a BGP update can de-peer a router
Aug 29, 2023FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
Aug 8, 2023