CVE-2024-31951
CVE-2024-31951: Buffer overflow vulnerability in FRRouting (FRR) allows for potential daemon crashes. This flaw affects the Opaque LSA Extended Link parser in FRR versions up to 9.1, specifically within the ospf_te_parse_ext_link function. The issue arises when processing OSPF LSA packets due to missing length validation when reading Segment Routing Adjacency SID subTLVs, leading to a buffer overflow. Despite a low SOCRadar Vulnerability Risk Score (SVRS) of 30, indicating less immediate criticality, the potential for a daemon crash could still disrupt network operations. While not immediately critical, this vulnerability should be addressed to maintain network stability. This overflow can be triggered remotely, making it a concern for network administrators using FRR.
Description:
CVE-2024-31951 is a buffer overflow vulnerability in FRRouting (FRR) that can lead to a daemon crash. The vulnerability is caused by an attempt to read Segment Routing Adjacency SID subTLVs without validating their lengths. This can lead to a buffer overflow and daemon crash.
Key Insights:
- The SVRS for CVE-2024-31951 is 38, indicating a moderate risk.
- The vulnerability is exploitable remotely, making it easy for attackers to exploit.
- The vulnerability can lead to a denial of service (DoS) attack, which can disrupt the availability of the affected system.
Mitigation Strategies:
- Update to FRRouting version 9.2 or later.
- Block access to the affected port (TCP port 8080).
- Implement a firewall to block unauthorized access to the affected system.
- Monitor the system for any suspicious activity.
Additional Information:
- There are no known active exploits for this vulnerability.
- CISA has not issued a warning for this vulnerability.
- The vulnerability is not known to be used in the wild.
If users have additional queries regarding this incident, they can use the 'Ask to Analyst' feature, contact SOCRadar directly, or open a support ticket for more information if necessary.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.