
Cloud Vulnerability DB
A community-led vulnerabilities database
BIRD through 2.0.7 does not provide functionality for password authentication of BGP peers. Because of this, products that use BIRD (which may, for example, include Tigera products in some configurations, as well as products of other vendors) may have been susceptible to route redirection for Denial of Service and/or Information Disclosure. This vulnerability was discovered in June 2021 and is tracked as CVE-2021-26928. The vulnerability is disputed as Tigera disagrees that the behavior is within their area of responsibility (CyberArk Research).
The vulnerability stems from BIRD's lack of password authentication functionality for BGP peers, which could allow an attacker to hijack BGP sessions. The attack involves stealing TCP sessions and manipulating BGP routing updates by sending forged NEXT_HOP values with more specific subnets. The vulnerability also leverages a logical flaw in BGP RFC4724 that enables persistent BGP hijacking through capability downgrade attacks (CyberArk Research).
The vulnerability could allow attackers to perform route redirection attacks leading to denial of service and/or information disclosure. An attacker who successfully exploits this vulnerability could place themselves in a man-in-the-middle position within the cluster, potentially intercepting and manipulating network traffic between pods (CyberArk Research).
The vulnerability requires a low-privileged user access on a node (master/worker) or on a pod with host network namespace. This could be achieved through various attack vectors such as running an RCE on a node's SCOM agent or accessing a pod with HostNetwork configured. The attack can be executed using simple network tools and crafted BGP messages (CyberArk Research).
Several mitigation steps are recommended: 1) Ensure pods are properly configured and not using HostNetwork mode unless necessary 2) Drop NET_RAW capability from pod settings to prevent packet manipulation 3) Implement TCP-MD5 authentication for BGP peers 4) Keep node OS and third-party software up to date. Tigera has released a fix in Calico v3.16.3 that allows users to configure a password to authenticate BGP peers (CyberArk Research).
The vulnerability led to disagreement between CyberArk Labs and Tigera regarding the nature of the vulnerability. While CyberArk Labs identified it as a design issue in Tigera's implementation, Tigera maintained that it was a flaw in the BGP protocol behavior. This resulted in the CVE being marked as disputed (CyberArk Research).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."