CVE-2021-43173
Last modified
CVE-2021-43173 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. EPSS estimates a 1.43% chance of exploitation in the next 30 days.
Description
In NLnet Labs Routinator prior to 0.10.2, a validation run can be delayed significantly by an RRDP repository by not answering but slowly drip-feeding bytes to keep the connection alive. This can be used to effectively stall validation. While Routinator has a configurable time-out value for RRDP connections, this time-out was only applied to individual read or write operations rather than the complete request. Thus, if an RRDP repository sends a little bit of data before that time-out expired, it can continuously extend the time it takes for the request to finish. Since validation will only continue once the update of an RRDP repository has concluded, this delay will cause validation to stall, leading to Routinator continuing to serve the old data set or, if in the initial validation run directly after starting, never serve any data at all.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nlnetlabs | Routinator | < 0.10.2 |
| Debian | Debian Linux | 11.0 |
References
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
- https://www.debian.org/security/2022/dsa-5041Third Party Advisory
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
- https://www.debian.org/security/2022/dsa-5041Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-43173?
How severe is CVE-2021-43173?
How do I fix CVE-2021-43173?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-43162A Remote Code Execution (RCE) vulnerability exists in Ruijie…8.8
- CVE-2021-43163A Remote Code Execution (RCE) vulnerability exists in Ruijie…9.8
- CVE-2021-43164A Remote Code Execution (RCE) vulnerability exists in Ruijie…8.8
- CVE-2021-4317Use after free in ANGLE in Google Chrome prior to 96.0.4664.…8.8
- CVE-2021-43171Improper verification of applications' cryptographic signatu…6.5
- CVE-2021-43172NLnet Labs Routinator prior to 0.10.2 happily processes a ch…7.5
- CVE-2021-43174NLnet Labs Routinator versions 0.9.0 up to and including 0.1…7.5
- CVE-2021-43175The GOautodial API prior to commit 3c3a979 made on October 1…7.5
- CVE-2021-43176The GOautodial API prior to commit 3c3a979 made on October 1…8.8
- CVE-2021-43177As a result of an incomplete fix for CVE-2015-7225, in versi…5.3
- CVE-2021-43178Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2021-43179Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
Are you affected by CVE-2021-43173?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
