CVE-2021-43114
Last modified
CVE-2021-43114 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.. EPSS estimates a 1.09% chance of exploitation in the next 30 days.
Description
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Fort Validator Project | Fort Validator | < 1.5.2 |
| Debian | Debian Linux | 11.0 |
References
- https://github.com/NICMx/FORT-validator/releases/tag/1.5.2Patch, Release Notes, Third Party Advisory
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
- https://github.com/NICMx/FORT-validator/releases/tag/1.5.2Patch, Release Notes, Third Party Advisory
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43114?
How severe is CVE-2021-43114?
How do I fix CVE-2021-43114?
Are you affected by CVE-2021-43114?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
