CVE-2023-46753 is a medium-severity vulnerability affecting FRRouting (FRR) versions up to 9.0.1, where a specially crafted BGP UPDATE message lacking mandatory attributes can cause a denial-of-service crash. This vulnerability has a CVSS score of 5.9, indicating a network-based attack with high impact on availability, but requiring high attack complexity. There is currently no public exploit code available (Metasploit, Nuclei, ExploitDB), nor is it listed on the CISA KEV catalog or Hot List, suggesting it is not being actively exploited. Community discussion and media coverage are minimal, with only one mention and one article identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 9.0.1CPE matchmatch criteria | cpe:2.3:a:frrouting:frrouting:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
CVE-2023-46753
Jun 11, 2024frr: crafted BGP UPDATE message leading to a crash
Oct 26, 2023An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur for a crafted BGP UPDATE message without mandatory attributes e.g. one with only an unknown transit attribute.
Oct 10, 2023