← Back to CVE Index
CVE-2023-47235
Disclosed 2023-11-03
Description
An issue was discovered in FRRouting FRR through 9.0.1. A crash can occur when a malformed BGP UPDATE message with an EOR is processed, because the presence of EOR does not lead to a treat-as-withdraw outcome.
Severity & CVSS Score
6.8
HIGH
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
High
Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:L/I:L/A:H
Affected FRR Versions
- < 8.5.4
- 9.0.0 ~ 9.0.1
Versions prior to 8.4 are end-of-life and no longer receive security updates.
References
| URL | Source |
|---|---|
| https://github.com/FRRouting/frr/commit/6814f2e0138a6ea5e1f83bdd9085d9a77999900b | GitHub |
Git Fixes
- 6814f2e0138a6ea5e1f83bdd9085d9a77999900b
- 837f57f087c997e3d66f7d1f86bdec3149917aba
- fc87cdbf07c1afa9ae6a32f3570501f4cb990ae3
- 01f232c227e566fec924472eb61cd6489a6e1d2b
- 3f79135cc7683f71732cfa24e05e4fe3eaf5df47
Raw Data
- CVE-2023-47235.cve.json — CVE record (JSON)
- CVE-2023-47235.frr.json — FRR-specific data (JSON)