CVE-2025-43971

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Apr 21, 2025
Updated: May 8, 2025
CWE ID 193

Summary

CVE-2025-43971 is a vulnerability affecting GoBGP before version 3.35.0. The issue lies in the pkg/packet/bgp/bgp.go file where a zero value for softwareVersionLen can lead to a panic, providing an opportunity for attackers to potentially exploit the system. This vulnerability could be exploited by sending maliciously crafted BGP messages to the affected GoBGP implementation, resulting in unexpected behavior or crashes. It is recommended that users upgrade to the latest version of GoBGP to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share