Vulnerability Description
Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Nokia | Service Router Linux | - |
| Nokia | Service Router Operating System | 22.10 |
Related Weaknesses (CWE)
References
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handlingExploitThird Party Advisory
- https://news.ycombinator.com/item?id=37305800Issue Tracking
- https://www.nokia.com/networks/technologies/service-router-operating-system/Product
- https://blog.benjojo.co.uk/post/bgp-path-attributes-grave-error-handlingExploitThird Party Advisory
- https://news.ycombinator.com/item?id=37305800Issue Tracking
- https://www.nokia.com/networks/technologies/service-router-operating-system/Product
FAQ
What is CVE-2023-41376?
CVE-2023-41376 is a vulnerability with a CVSS score of 7.5 (HIGH). Nokia Service Router Operating System (SR OS) 22.10 and SR Linux, when error-handling update-fault-tolerance is not enabled, mishandle BGP path attributes.
How severe is CVE-2023-41376?
CVE-2023-41376 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-41376?
Check the references section above for vendor advisories and patch information. Affected products include: Nokia Service Router Linux, Nokia Service Router Operating System.