First published: Fri Jun 04 2021(Updated: )
** DISPUTED ** BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NIC BIRD | <=2.0.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2021-26928.
The severity of CVE-2021-26928 is medium, with a severity value of 6.8.
There is currently no fix available for CVE-2021-26928.