CVE-2024-56170
Last modified
CVE-2024-56170 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. EPSS estimates a 0.20% chance of exploitation in the next 30 days.
Description
A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everything else is correct, the most recent version of a manifest should be prioritized over other versions, to prevent replays, accidental or otherwise. Manifests contain the manifestNumber and thisUpdate fields, which can be used to gauge the relevance of a given manifest, when compared to other manifests. The former is a serial-like sequential number, and the latter is the date on which the manifest was created. However, the product does not compare the up-to-dateness of the most recently fetched manifest against the cached manifest. As such, it's prone to a rollback to a previous version if it's served a valid outdated manifest. This leads to outdated route origin validation.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Nicmx | Fort-Validator | <= 1.6.6 |
References
- https://nicmx.github.io/FORT-validator/CVE.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-56170?
How severe is CVE-2024-56170?
How do I fix CVE-2024-56170?
How Strix Helps
- Same Subject, Wrong User: A Cross-Issuer Account Takeover in n8nStrix found an identity-binding bug in n8n's token-exchange flow enabling account takeover.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-56157iTop is an web based IT Service Management tool. Prior to ve…6.3
- CVE-2024-56158XWiki is a generic wiki platform. It's possible to execute a…9.8
- CVE-2024-56159Astro is a web framework for content-driven websites. A bug …5.3
- CVE-2024-5616A Cross-Site Request Forgery (CSRF) vulnerability exists in …4.3
- CVE-2024-56161Improper signature verification in AMD CPU ROM microcode pat…7.2
- CVE-2024-56169A validation integrity issue was discovered in Fort through …5.3
- CVE-2024-56171libxml2 before 2.12.10 and 2.13.x before 2.13.6 has a use-af…9.8
- CVE-2024-56173In Optimizely Configured Commerce before 5.2.2408, malicious…4.7
- CVE-2024-56174In Optimizely Configured Commerce before 5.2.2408, malicious…8.1
- CVE-2024-56175In Optimizely Configured Commerce before 5.2.2408, malicious…6.1
- CVE-2024-56178An issue was discovered in Couchbase Server 7.6.x through 7.…6.5
- CVE-2024-56179In MindManager Windows versions prior to 24.1.150, attackers…7.8
Are you affected by CVE-2024-56170?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
