CVE-2023-38283: Medium severity openbgpd vulnerability
Published Aug 29, 2023
·Updated
In OpenBGPD before 8.1, incorrect handling of BGP update data (length of path attributes) set by a potentially distant remote actor may cause the system to incorrectly reset a session. This is fixed in OpenBSD 7.3 errata 006.
Affected Software
8 affected components
OpenBGPD OpenBGPD<8.1
OpenBSD OpenBSD<7.3
OpenBSD OpenBSD=7.3
OpenBSD OpenBSD=7.3-errata_001
OpenBSD OpenBSD=7.3-errata_002
OpenBSD OpenBSD=7.3-errata_003
OpenBSD OpenBSD=7.3-errata_004
OpenBSD OpenBSD=7.3-errata_005
Remediation
Event History
Aug 29, 2023
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
What is the vulnerability ID for this OpenBGPD vulnerability?
The vulnerability ID for this OpenBGPD vulnerability is CVE-2023-38283.
2
What is the severity of CVE-2023-38283?
The severity of CVE-2023-38283 is medium with a severity value of 5.3.
3
How does this vulnerability impact OpenBGPD?
This vulnerability in OpenBGPD could potentially cause the system to incorrectly reset a session.
4
Can the OpenBGPD vulnerability affect OpenBSD 7.3?
No, OpenBGPD vulnerability does not affect OpenBSD 7.3.
5
How can I fix CVE-2023-38283 in OpenBGPD?
To fix CVE-2023-38283 in OpenBGPD, you should update to OpenBGPD version 8.1 or apply the OpenBSD 7.3 errata 006 patch.