CVE-2024-45238
Last modified
CVE-2024-45238 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. EPSS estimates a 0.30% chance of exploitation in the next 30 days.
Description
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a bit string that doesn't properly decode into a Subject Public Key. OpenSSL does not report this problem during parsing, and when compiled with OpenSSL libcrypto versions below 3, Fort recklessly dereferences the pointer. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nicmx | Fort Validator | < 1.6.3 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2024-45238?
How severe is CVE-2024-45238?
How do I fix CVE-2024-45238?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-45232An issue was discovered in powermail extension through 12.3.…5.3
- CVE-2024-45233An issue was discovered in powermail extension through 12.3.…9.8
- CVE-2024-45234An issue was discovered in Fort before 1.6.3. A malicious RP…7.5
- CVE-2024-45235An issue was discovered in Fort before 1.6.3. A malicious RP…7.5
- CVE-2024-45236An issue was discovered in Fort before 1.6.3. A malicious RP…7.5
- CVE-2024-45237An issue was discovered in Fort before 1.6.3. A malicious RP…9.8
- CVE-2024-45239An issue was discovered in Fort before 1.6.3. A malicious RP…7.5
- CVE-2024-4524A vulnerability, which was classified as problematic, was fo…6.1
- CVE-2024-45240The TikTok (aka com.zhiliaoapp.musically) application before…7.4
- CVE-2024-45241A traversal vulnerability in GeneralDocs.aspx in CentralSqua…7.5
- CVE-2024-45242EnGenius ENH1350EXT A8J-ENH1350EXT devices through 3.9.3.2_c…7.8
- CVE-2024-45244Hyperledger Fabric through 3.0.0 and 2.5.x through 2.5.9 do …5.3
Are you affected by CVE-2024-45238?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
