BGP Peering Vulnerability in BIRD Software by Tigera
CVE-2021-26928

6.8MEDIUM

Key Information:

Vendor

Nic

Status
Vendor
CVE Published:
4 June 2021

What is CVE-2021-26928?

The BIRD software prior to version 2.0.7 lacks essential password authentication for BGP peers, making it vulnerable to potential route redirection attacks. This can lead to Denial of Service (DoS) scenarios or the unintentional disclosure of sensitive information. Although Tigera claims the observed behavior falls outside their responsibility, it is important for users of affected BIRD configurations to consider their exposure to these risks.

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.