CVE-2024-55553

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Jan 6, 2025
Updated: Jan 23, 2025
CWE ID 404

Summary

CVE-2024-55553 is a vulnerability affecting FRRouting (FRR) versions before 10.3. When an update received via RTR exceeds the internal socket's default buffer size of 4KB, all routes are re-validated, causing potential performance issues and increased BMP traffic. An attacker can exploit this by issuing a large number of updates within an update interval of usually 30 minutes, leading to continuous route validation and potential impact on routers with large full tables. The vulnerability can also be triggered organically, making it a significant concern for FRR instances using RPKI globally. Versions 10.0.3, 10.1.2, 10.2.1, and 10.3 address this issue.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share