BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. NOTE: a researcher has asserted that the behavior is within Tigera’s area of responsibility; however, Tigera disagrees
Metrics
Affected Vendors & Products
References
History
Wed, 25 Feb 2026 11:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:nic:bird:2.0.7:*:*:*:*:*:*:* | |
| Metrics |
ssvc
|
Status: PUBLISHED
Assigner: mitre
Published: 2021-06-04T20:13:28.000Z
Updated: 2024-08-03T20:33:41.334Z
Reserved: 2021-02-09T00:00:00.000Z
Link: CVE-2021-26928
Updated: 2024-08-03T20:33:41.334Z
Status : Modified
Published: 2021-06-04T21:15:07.433
Modified: 2024-11-21T05:57:03.797
Link: CVE-2021-26928
No data.