CVE-2024-27913
MEDIUM 6.5EPSS 0.3%
ospf_te_parse_te in ospfd/ospf_te.c in FRRouting (FRR) through 9.1 allows remote attackers to cause a denial of service (ospfd daemon crash) via a malformed OSPF LSA packet, because of an attempted access to a missing attribute field.
- CVSS v3.1
- 6.5 MEDIUM
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - CVSS v3.1
- 6.2 MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H - EPSS
- 0.32% chance of exploitation in the next 30 days, 25th percentile
- Published
- 2024-02-28
- Updated
- 2025-03-26
Proof-of-concept exploits (1)
- AimiP02/OSPF_BooFuzzer2★ · 2024-07-13