Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2023-46753

20
FAUCET Score

CVE-2023-46753 is a medium-severity vulnerability affecting FRRouting (FRR) versions up to 9.0.1, where a specially crafted BGP UPDATE message lacking mandatory attributes can cause a denial-of-service crash. This vulnerability has a CVSS score of 5.9, indicating a network-based attack with high impact on availability, but requiring high attack complexity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the CISA KEV catalog or Hot List, suggesting it is not being actively exploited. Community discussion and media coverage are minimal, with only one mention and one article identified.

Impacted Technologies

VendorProductVersion(s)CPE
<= 9.0.1CPE matchmatch criteria
cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

5.9MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
NONE
Integrity Impact
NONE
Availability Impact
HIGH
Exploitability Score
2.2
Impact Score
3.6
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.78%
Probability of exploitation in next 30 days
EPSS Percentile
52.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
This CVE's current EPSS score of 0.0078 is in the 11th percentile among its peer group of 19,958 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (10)

github_advisorypatch availablevia nvd_reference
View patch
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 ARMFixed in: 9.1-2
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 ARMFixed in: 8.5.3-3
microsoftpatch availablevia msrc
Product: Azure Linux 3.0 x64Fixed in: 9.1-2
microsoftpatch availablevia msrc
Product: azl3 frr 8.5.3-2 on Azure Linux 3.0Fixed in: 9.1-2
microsoftpatch availablevia msrc
Product: azl3 frr 9.1-2 on Azure Linux 3.0Fixed in: 9.1-2
microsoftpatch availablevia msrc
Product: cbl2 frr 8.5.3-3 on CBL Mariner 2.0Fixed in: 8.5.3-3
microsoftpatch availablevia msrc
Product: CBL Mariner 2.0 x64Fixed in: 8.5.3-3
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 9Fixed in: frr-0:8.5.3-4.el9
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 8Fixed in: frr-0:7.5.1-22.el8
View patch

Vendor Advisories (3)

microsoft2024-Jun/CVE-2023-46753

CVE-2023-46753

Jun 11, 2024
redhatCVE-2023-46753Moderate

frr: crafted BGP UPDATE message leading to a crash

Oct 26, 2023
microsoft2023-Oct/CVE-2023-46753Moderate

An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.

Oct 10, 2023

References

lists.debian.org / debian-lts-announce/2024/09/msg00007.html
github.com / FRRouting/frr/pull/14645/commits/d8482bf011cb2b173e85b65b4bf3d5061250cdb9
Patch
lists.debian.org / debian-lts-announce/2024/04/msg00019.html