CVE Radar Logo
CVERadar
CVE Radar Logo
CVERadar

CVE-2024-44070

High Severity
Frrouting
SVRS
68/100

CVSSv3
7.5/10

EPSS
0.00154/1

CVE-2024-44070: Discover a critical vulnerability in FRRouting (FRR) impacting versions through 10.1. This BGP vulnerability in bgpd/bgp_attr.c doesn't properly validate stream length, potentially leading to a buffer overflow.

CVE-2024-44070 affects FRRouting (FRR) by failing to check the remaining stream length in the bgp_attr_encap function before processing TLV values. This flaw exposes systems to the risk of remote code execution if exploited by a malicious actor. With a SOCRadar Vulnerability Risk Score (SVRS) of 68, while not critical, CVE-2024-44070 represents a serious risk. Immediate patching and mitigation strategies are highly recommended to prevent potential exploitation. The improper handling of stream length could lead to denial-of-service or the execution of arbitrary code, making it vital for administrators to address this security flaw promptly.

No tags available
CVSS:3.1
AV:N
AC:L
PR:N
UI:N
S:U
C:N
I:N
A:H
2025-03-13

2024-08-19

Indicators of Compromise

No IOCs found for this CVE

Exploits

No exploits found for this CVE

Enhance Your CVE Management with SOCRadar Vulnerability Intelligence
Get comprehensive CVE details, real-time notifications, and proactive threat management all in one platform.
CVE Details
Access comprehensive CVE information instantly
Real-time Tracking
Subscribe to CVEs and get instant updates
Exploit Analysis
Monitor related APT groups and threats
IOC Tracking
Analyze and track CVE-related IOCs

News

USN-7230-2: FRR vulnerabilities
2025-01-28
USN-7230-2: FRR vulnerabilities | Iggy Frankovic discovered that FRR incorrectly handled certain BGP messages. A remote attacker could possibly use this issue to cause FRR to crash, resulting in a denial of service. This issue only affected Ubuntu 20.04 LTS. (CVE-2024-44070) It was discovered that FRR re-validated all routes in certain instances when the internal socket's buffer size overflowed. A remote attacker could possibly use this issue to impact the performance of FRR, resulting in a denial of service. (CVE-2024-55553)
cve-2024-44070
cve-2024-55553
ubuntu
messages
CVE-2024-44070 | FRRouting up to 10.1 bgpd/bgp_attr.c bgp_attr_encap TLV memory corruption (Nessus ID 207784)
vuldb.com2024-09-28
CVE-2024-44070 | FRRouting up to 10.1 bgpd/bgp_attr.c bgp_attr_encap TLV memory corruption (Nessus ID 207784) | A vulnerability was found in FRRouting up to 10.1 and classified as critical. This issue affects the function bgp_attr_encap of the file bgpd/bgp_attr.c. The manipulation of the argument TLV leads to memory corruption. The identification of this vulnerability is <a href="https://
cve-2024-44070
domains
urls
cves

Social Media

[CVE-2024-44070: CRITICAL] An issue was discovered in FRRouting (FRR) through 10.1. bgp_attr_encap in bgpd/bgp_attr.c does not check the actual remaining stream length before taking the TLV value.#cybersecurity,#vulnerability https://t.co/slpXHNLdSw https://t.co/9dZ0BVdW5l
0
0
0

Affected Software

Configuration 1
TypeVendorProduct
AppFrroutingfrrouting
Configuration 2
TypeVendorProduct
OSRedhatenterprise_linux

References

ReferenceLink
[email protected]https://github.com/FRRouting/frr/pull/16497

CWE Details

No CWE details found for this CVE

CVE Radar

Real-time CVE Intelligence & Vulnerability Management Platform

CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.

Get Free Vulnerability Intelligence AccessAccess real-time CVE monitoring, exploit analysis, and threat intelligence