OSPFD Daemon Crash Vulnerability in FRR Through 9.1 Due to Malformed OSPF LSA Packet
CVE-2024-27913

6.5MEDIUM

Key Information:

Status
Vendor
CVE Published:
28 February 2024

What is CVE-2024-27913?

ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Adjacent Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.