Denial of Service Vulnerability in FRRouting and Pica8 Products
CVE-2023-38802
7.5HIGH
What is CVE-2023-38802?
A vulnerability exists in FRRouting FRR from versions 7.5.1 to 9.0 and Pica8 PICOS 4.3.3.2, allowing remote attackers to trigger a denial of service. This can be achieved by sending a specially crafted BGP update containing a corrupted attribute, specifically attribute 23 (Tunnel Encapsulation). Exploitation of this vulnerability can disrupt network services, highlighting the importance of timely updates and monitoring of BGP updates in affected systems.