WGSA-2023-00010

FRR Dynamic Routing Denial of Service Vulenrabilities

High Published 2023-12-15Updated 2026-07-28

Summary #

BGP software such as FRRRouting FRR and Quagga included as part of Fireware OS enable a remote attacker to incorrectly reset network sessions through an invalid BGP update. This vulnerability is only applicable to Firebox appliances with BGP routing features enabled.

CVE identifiers #

CVE IDDescriptionCVSS
CVE-2023-38802 FRRouting FRR 7.5.1 through 9.0 and Pica8 PICOS 4.3.3.2 allow a remote attacker to cause a denial of service via a crafted BGP update with a corrupted attribute 23 (Tunnel Encapsulation).
CVE-2023-41358 An issue was discovered in FRRouting FRR through 9.0. bgpd/bgp_packet.c processes NLRIs if the attribute length is zero.

Product status #

ProductAffectedNot affected
Fireware OS>= 12.1.1, < 12.10.1>= 12.10.1

Solution #

Fireware OS 12.10.1

References #