Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-26928


BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees


Published

2021-06-04T21:15:07.433

Last Modified

2024-11-21T05:57:03.797

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.8 (MEDIUM)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:N/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: NONE
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

4.9

Weaknesses
  • Type: Primary
    CWE-306
  • Type: Secondary
    CWE-306

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application nic bird ≤ 2.0.7 Yes

References