← back
CVE-2024-31948mediumCWE-1287

CVE-2024-31948

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.8%
exploitation probability
0.8%top 44% of all CVEs
observed exploitation
nono source reports it
In short

An attacker can crash the BGP routing daemon in FRRouting by sending a specially crafted network packet with malformed data. This causes the routing service to stop working, disrupting network traffic routing.

Technical detail

The bgpd daemon in FRRouting versions through 9.1 fails to properly validate Prefix SID attributes in BGP UPDATE packets, allowing a network-adjacent attacker to trigger a denial-of-service condition through a crafted packet that causes the daemon to crash without requiring authentication.

Summary generated and translated by AI from the official description.
In FRRouting (FRR) through 9.1, an attacker using a malformed Prefix SID attribute in a BGP UPDATE packet can cause the bgpd daemon to crash.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Affected products
n/a · n/a