First published: Tue Oct 24 2023(Updated: )
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
F5 BIG-IP Next | >=20.0.1<=20.1.0 | |
F5 BIG-IP Next SPK | >=1.5.0<=1.9.1 | |
F5 BIG-IP Next CNF | >=1.1.0<=1.2.1 | |
F5 BIG-IP | >=17.1.0<=17.1.1 | |
F5 BIG-IP | >=16.1.0<=16.1.4 | |
F5 BIG-IP | >=15.1.0<=15.1.10 | |
F5 BIG-IP | >=14.1.0<=14.1.5 | |
F5 BIG-IP | >=13.1.0<=13.1.5 | |
F5 BIG-IP Next | =20.0.1 | |
F5 Big-ip Next Service Proxy For Kubernetes | >=1.5.0<=1.8.2 | |
F5 Big-ip Next Cloud-native Network Functions | >=1.1.0<=1.1.1 | |
F5 Big-ip Local Traffic Manager | >=13.1.0<=13.1.5 | |
F5 Big-ip Local Traffic Manager | >=14.1.0<=14.1.5 | |
F5 Big-ip Local Traffic Manager | >=15.1.0<=15.1.10 | |
F5 Big-ip Local Traffic Manager | >=16.1.0<=16.1.4 | |
F5 Big-ip Local Traffic Manager | >=17.1.0<=17.1.1 | |
F5 Big-ip Global Traffic Manager | >=13.1.0<=13.1.5 | |
F5 Big-ip Global Traffic Manager | >=14.1.0<=14.1.5 | |
F5 Big-ip Global Traffic Manager | >=15.1.0<=15.1.10 | |
F5 Big-ip Global Traffic Manager | >=16.1.0<=16.1.4 | |
F5 Big-ip Global Traffic Manager | >=17.1.0<=17.1.1 | |
Ipinfusion Zebos | <=7.10.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45886 is a vulnerability in the BGP daemon (bgpd) in IP Infusion ZebOS through version 7.10.6 that allows remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
The severity of CVE-2023-45886 is high with a CVSS score of 7.5.
The following software versions are affected by CVE-2023-45886: F5 Big-ip Next (version 20.0.1), F5 Big-ip Next Service Proxy For Kubernetes (versions 1.5.0 to 1.8.2), F5 Big-ip Next Cloud-native Network Functions (versions 1.1.0 to 1.1.1), F5 Big-ip Local Traffic Manager (versions 13.1.0 to 13.1.5, 14.1.0 to 14.1.5, 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, 17.1.0 to 17.1.1), and F5 Big-ip Global Traffic Manager (versions 13.1.0 to 13.1.5, 14.1.0 to 14.1.5, 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, 17.1.0 to 17.1.1).
CVE-2023-45886 can be exploited by remote attackers sending crafted BGP update messages containing a malformed attribute.
You can find more information about CVE-2023-45886 at the following references: [1] https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling [2] https://www.kb.cert.org/vuls/id/347067 [3] https://www.ipinfusion.com/doc_prod_cat/zebos/