Lucene search

K
cve[email protected]CVE-2023-4809
HistorySep 06, 2023 - 8:15 p.m.

CVE-2023-4809

2023-09-0620:15:08
CWE-167
web.nvd.nist.gov
22
cve
2023
4809
ipv6
fragment headers
packet processing
firewall rules

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%

In pf packet processing with a ‘scrub fragment reassemble’ rule, a packet containing multiple IPv6 fragment headers would be reassembled, and then immediately processed. That is, a packet with multiple fragment extension headers would not be recognized as the correct ultimate payload. Instead a packet with multiple IPv6 fragment headers would unexpectedly be interpreted as a fragmented packet, rather than as whatever the real payload is.

As a result, IPv6 fragments may bypass pf firewall rules written on the assumption all fragments have been reassembled and, as a result, be forwarded or processed by the host.

Affected configurations

NVD
Node
freebsdfreebsdRange<12.4
OR
freebsdfreebsdRange13.013.2
OR
freebsdfreebsdMatch12.4-
OR
freebsdfreebsdMatch12.4p1
OR
freebsdfreebsdMatch12.4p2
OR
freebsdfreebsdMatch12.4p3
OR
freebsdfreebsdMatch12.4p4
OR
freebsdfreebsdMatch12.4rc2-p1
OR
freebsdfreebsdMatch12.4rc2-p2
OR
freebsdfreebsdMatch13.2-
OR
freebsdfreebsdMatch13.2p1
OR
freebsdfreebsdMatch13.2p2

CNA Affected

[
  {
    "defaultStatus": "unknown",
    "modules": [
      "pf"
    ],
    "product": "FreeBSD",
    "vendor": "FreeBSD",
    "versions": [
      {
        "lessThan": "p3",
        "status": "affected",
        "version": "13.2-RELEASE",
        "versionType": "release"
      },
      {
        "lessThan": "p5",
        "status": "affected",
        "version": "12.4-RELEASE",
        "versionType": "release"
      }
    ]
  }
]

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

7.6 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.6%