Lucene search

K
cve[email protected]CVE-2023-3107
HistoryAug 01, 2023 - 11:15 p.m.

CVE-2023-3107

2023-08-0123:15:30
CWE-190
web.nvd.nist.gov
18
cve-2023-3107
ipv6
integer overflow
denial of service
kernel panic
nvd

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.0%

A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet’s payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.

Affected configurations

NVD
Node
freebsdfreebsdMatch12.4-
OR
freebsdfreebsdMatch12.4p1
OR
freebsdfreebsdMatch12.4p2
OR
freebsdfreebsdMatch12.4p3
OR
freebsdfreebsdMatch12.4rc2-p1
OR
freebsdfreebsdMatch12.4rc2-p2
OR
freebsdfreebsdMatch13.1-
OR
freebsdfreebsdMatch13.1b1-p1
OR
freebsdfreebsdMatch13.1b2-p2
OR
freebsdfreebsdMatch13.1p1
OR
freebsdfreebsdMatch13.1p2
OR
freebsdfreebsdMatch13.1p3
OR
freebsdfreebsdMatch13.1p4
OR
freebsdfreebsdMatch13.1p5
OR
freebsdfreebsdMatch13.1p6
OR
freebsdfreebsdMatch13.1p7
OR
freebsdfreebsdMatch13.1p8
OR
freebsdfreebsdMatch13.1rc1-p1
OR
freebsdfreebsdMatch13.2-
OR
freebsdfreebsdMatch13.2p1
Node
netappclustered_data_ontapMatch9.0-

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "ipv6"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "13.2-RELEASE-p2",
        "status": "affected",
        "version": "13.2-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "13.1-RELEASE-p9",
        "status": "affected",
        "version": "13.1-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "12.4-RELEASE-p4",
        "status": "affected",
        "version": "12.4-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

7.3 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

23.0%