Skip to main content

Improper Validation of Integrity Check Value

CVE-2023-38802

Severity High
Score 7.5/10

Summary

FRRouting FRR 7.5.1 through 8.5.2 , 9.0-dev through 9.0, and 9.1-dev. Allow a remote attacker to cause a Denial Of Service (DOS) via a crafted "BGP" update with a corrupted attribute 23 (Tunnel Encapsulation).

  • LOW
  • NETWORK
  • NONE
  • UNCHANGED
  • NONE
  • NONE
  • NONE
  • HIGH

CWE-354 - Improper Validation of Integrity Check Value

The software does not validate or incorrectly validates the integrity check values or "checksums" of a message. This may prevent it from detecting if the data has been modified or corrupted in transmission.

Advisory Timeline

  • Published