CVE-2023-45886: High severity F5 BIG-IP Next vulnerability
The BGP daemon (bgpd) in IP Infusion ZebOS through 7.10.6 allow remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
Other sources
The BGP daemon (bgpd) in ZebOS through 7.10.6 allows remote attackers to cause a denial-of-service (DoS) by sending crafted BGP update messages containing a malformed attribute.
— F5
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-45886?
CVE-2023-45886 is a vulnerability in the BGP daemon (bgpd) in IP Infusion ZebOS through version 7.10.6 that allows remote attackers to cause a denial of service by sending crafted BGP update messages containing a malformed attribute.
What is the severity of CVE-2023-45886?
The severity of CVE-2023-45886 is high with a CVSS score of 7.5.
Which software is affected by CVE-2023-45886?
The following software versions are affected by CVE-2023-45886: F5 Big-ip Next (version 20.0.1), F5 Big-ip Next Service Proxy For Kubernetes (versions 1.5.0 to 1.8.2), F5 Big-ip Next Cloud-native Network Functions (versions 1.1.0 to 1.1.1), F5 Big-ip Local Traffic Manager (versions 13.1.0 to 13.1.5, 14.1.0 to 14.1.5, 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, 17.1.0 to 17.1.1), and F5 Big-ip Global Traffic Manager (versions 13.1.0 to 13.1.5, 14.1.0 to 14.1.5, 15.1.0 to 15.1.10, 16.1.0 to 16.1.4, 17.1.0 to 17.1.1).
How can CVE-2023-45886 be exploited?
CVE-2023-45886 can be exploited by remote attackers sending crafted BGP update messages containing a malformed attribute.
Is there any additional information available about CVE-2023-45886?
You can find more information about CVE-2023-45886 at the following references: [1] https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handling [2] https://www.kb.cert.org/vuls/id/347067 [3] https://www.ipinfusion.com/doc_prod_cat/zebos/