A set of carefully crafted ipv6 packets can trigger an integer overflow in the calculation of a fragment reassembled packet's payload length field. This allows an attacker to trigger a kernel panic, resulting in a denial of service.
Conclusion & alert: CVE-2023-3107 is rated Moderate Risk (44.8/100): CVSS High severity, with low exploitation likelihood (EPSS 0.21%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2025-11-21 | 0.68% | 0.21% | -0.47% |
| 2 | 2025-11-18 | 0.16% | 0.68% | +0.51% |
| 3 | 2025-07-13 | — | 0.16% | — |
Full EPSS history (13 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | [email protected] |
| 7.5 | 3.1 | HIGH |
|
3.9 | 3.6 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:-:*:*:*:*:*:* |
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p1:*:*:*:*:*:* |
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p2:*:*:*:*:*:* |
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:p3:*:*:*:*:*:* |
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:rc2-p1:*:*:*:*:*:* |
| freebsd | freebsd | 12.4 | cpe:2.3:o:freebsd:freebsd:12.4:rc2-p2:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:-:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:b1-p1:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:b2-p2:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p1:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p2:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p3:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p4:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p5:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p6:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p7:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:p8:*:*:*:*:*:* |
| freebsd | freebsd | 13.1 | cpe:2.3:o:freebsd:freebsd:13.1:rc1-p1:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:-:*:*:*:*:*:* |
| freebsd | freebsd | 13.2 | cpe:2.3:o:freebsd:freebsd:13.2:p1:*:*:*:*:*:* |
| netapp | clustered_data_ontap | 9.0 | cpe:2.3:a:netapp:clustered_data_ontap:9.0:-:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://security.FreeBSD.org/advisories/FreeBSD-SA-23:06.ipv6.asc | Mitigation Vendor Advisory |
| https://security.netapp.com/advisory/ntap-20230804-0001/ | Third Party Advisory |