PageSourceSearch

https://docs-spectrocloud.netlify.app/assets/js/07238394.068c6cc2.js

js docs-spectrocloud.netlify.app collected 2026-10-03 10:42:34 UTC 7,085 bytes, 1 lines download raw bytes

1"use strict";(self.webpackChunkspectro_cloud_docs=self.webpackChunkspectro_cloud_docs||[]).push([["14054"],{673060:function(e,t,i){i.r(t),i.d(t,{frontMatter:()=>l,toc:()=>d,default:()=>h,metadata:()=>r,assets:()=>c,contentTitle:()=>a});var r=JSON.parse('{"id":"security-bulletins/reports/va-cve-2025-43971","title":"CVE-2025-43971","description":"Lifecycle of CVE-2025-43971","source":"@site/docs/docs-content/security-bulletins/reports/va-cve-2025-43971.md","sourceDirName":"security-bulletins/reports","slug":"/security-bulletins/reports/va-cve-2025-43971","permalink":"/security-bulletins/reports/va-cve-2025-43971","draft":false,"unlisted":false,"editUrl":"https://github.com/spectrocloud/librarium/blob/master/docs/docs-content/security-bulletins/reports/va-cve-2025-43971.md","tags":[{"inline":true,"label":"security","permalink":"/tags/security"},{"inline":true,"label":"cve","permalink":"/tags/cve"}],"version":"current","lastUpdatedAt":null,"frontMatter":{"sidebar_label":"CVE-2025-43971","title":"CVE-2025-43971","description":"Lifecycle of CVE-2025-43971","sidebar_class_name":"hide-from-sidebar","hide_table_of_contents":false,"toc_max_heading_level":2,"tags":["security","cve"]},"sidebar":"docSidebar","previous":{"title":"CVE-2025-32990","permalink":"/security-bulletins/reports/va-cve-2025-32990"},"next":{"title":"CVE-2025-43972","permalink":"/security-bulletins/reports/va-cve-2025-43972"}}'),s=i(474848),n=i(884429);let l={sidebar_label:"CVE-2025-43971",title:"CVE-2025-43971",description:"Lifecycle of CVE-2025-43971",sidebar_class_name:"hide-from-sidebar",hide_table_of_contents:!1,toc_max_heading_level:2,tags:["security","cve"]},a,c={},d=[{value:"CVE Details",id:"cve-details",level:2},{value:"Initial Publication",id:"initial-publication",level:2},{value:"Last Update",id:"last-update",level:2},{value:"Third Party Dependency",id:"third-party-dependency",level:2},{value:"NIST CVE Summary",id:"nist-cve-summary",level:2},{value:"CVE Severity",id:"cve-severity",level:2},{value:"Our Official Summary",id:"our-official-summary",level:2},{value:"Status",id:"status",level:2},{value:"Affected Products & Versions",id:"affected-products--versions",level:2},{value:"Revision History",id:"revision-history",level:2}];function o(e){let t={a:"a",h2:"h2",p:"p",table:"table",tbody:"tbody",td:"td",th:"th",thead:"thead",tr:"tr",...(0,n.R)(),...e.components};return(0,s.jsxs)(s.Fragment,{children:[(0,s.jsx)(t.h2,{id:"cve-details",children:"CVE Details"}),"\n",(0,s.jsxs)(t.p,{children:["Visit the official vulnerability details page for ",(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-43971",children:"CVE-2025-43971"})," to learn more."]}),"\n",(0,s.jsx)(t.h2,{id:"initial-publication",children:"Initial Publication"}),"\n",(0,s.jsx)(t.p,{children:"04/22/2025"}),"\n",(0,s.jsx)(t.h2,{id:"last-update",children:"Last Update"}),"\n",(0,s.jsx)(t.p,{children:"09/17/2025"}),"\n",(0,s.jsx)(t.h2,{id:"third-party-dependency",children:"Third Party Dependency"}),"\n",(0,s.jsx)(t.p,{children:"github.com/osrg/gobgp/v3"}),"\n",(0,s.jsx)(t.h2,{id:"nist-cve-summary",children:"NIST CVE Summary"}),"\n",(0,s.jsx)(t.p,{children:"An issue was discovered in GoBGP before 3.35.0. pkg/packet/bgp/bgp.go allows attackers to cause a panic via a zero value for softwareVersionLen."}),"\n",(0,s.jsx)(t.h2,{id:"cve-severity",children:"CVE Severity"}),"\n",(0,s.jsx)(t.p,{children:(0,s.jsx)(t.a,{href:"https://nvd.nist.gov/vuln/detail/cve-2025-43971",children:"7.5"})}),"\n",(0,s.jsx)(t.h2,{id:"our-official-summary",children:"Our Official Summary"}),"\n",(0,s.jsx)(t.p,{children:"The vulnerability originates from a flaw in the pkg/packet/bgp/bgp.go file in GoBGP versions prior to 3.35.0. Specifically, if the softwareVersionLen field is set to zero, it can trigger a panic within the application, resulting in a crash."}),"\n",(0,s.jsx)(t.p,{children:"The risk of exploitation is low, as it requires privileged access and the ability to execute code within the container. Furthermore, the overall impact is limited due to the containerized environment, which restricts the available attack surface. Upstream patches addressing this issue are available and will be adopted to resolve the vulnerability."}),"\n",(0,s.jsx)(t.h2,{id:"status",children:"Status"}),"\n",(0,s.jsx)(t.p,{children:"Ongoing"}),"\n",(0,s.jsx)(t.h2,{id:"affected-products--versions",children:"Affected Products & Versions"}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Version"}),(0,s.jsx)(t.th,{children:"Palette Enterprise"}),(0,s.jsx)(t.th,{children:"Palette Enterprise Airgap"}),(0,s.jsx)(t.th,{children:"VerteX"}),(0,s.jsx)(t.th,{children:"VerteX Airgap"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.7.16"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u2705 No Impact"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"4.6.41"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"}),(0,s.jsx)(t.td,{children:"\u26A0\uFE0F Impacted"})]})]})]}),"\n",(0,s.jsx)(t.h2,{id:"revision-history",children:"Revision History"}),"\n",(0,s.jsxs)(t.table,{children:[(0,s.jsx)(t.thead,{children:(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.th,{children:"Date"}),(0,s.jsx)(t.th,{children:"Revision"})]})}),(0,s.jsxs)(t.tbody,{children:[(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"08/12/2025"}),(0,s.jsx)(t.td,{children:"Official summary revised: The vulnerability originates from a flaw in the pkg/packet/bgp/bgp.go file in GoBGP versions prior to 3.35.0. Specifically, if the softw
1areVersionLen field is set to zero, it can trigger a panic within the application, resulting in a crash.The risk of exploitation is low, as it requires privileged access and the ability to execute code within the container. Furthermore, the overall impact is limited due to the containerized environment, which restricts the available attack surface. Upstream patches addressing this issue are available and will be adopted to resolve the vulnerability."})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"05/20/2025"}),(0,s.jsx)(t.td,{children:"Status changed from Open to Ongoing"})]}),(0,s.jsxs)(t.tr,{children:[(0,s.jsx)(t.td,{children:"05/15/2025"}),(0,s.jsx)(t.td,{children:"Advisory severity revised to HIGH from"})]})]})]})]})}function h(e={}){let{wrapper:t}={...(0,n.R)(),...e.components};return t?(0,s.jsx)(t,{...e,children:(0,s.jsx)(o,{...e})}):o(e)}},884429:function(e,t,i){i.d(t,{R:()=>l,x:()=>a});var r=i(296540);let s={},n=r.createContext(s);function l(e){let t=r.useContext(n);return r.useMemo(function(){return"function"==typeof e?e(t):{...t,...e}},[t,e])}function a(e){let t;return t=e.disableParentContext?"function"==typeof e.components?e.components(s):e.components||s:l(e.components),r.createElement(n.Provider,{value:t},e.children)}}}]);

Line numbers count LF bytes from the start of the resource, as the search results do. Vendor segments are library code the classifier recognised; they are stored but not indexed. Bytes are shown as Latin1 characters, one per byte.