Vulnerability Description
FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Fort Validator Project | Fort Validator | < 1.5.2 |
| Debian | Debian Linux | 11.0 |
References
- https://github.com/NICMx/FORT-validator/commit/274dc14aed1eb9b3350029d1063578a6b
- https://github.com/NICMx/FORT-validator/commit/425e0f4037b4543fe8044ac96ca71d6d0
- https://github.com/NICMx/FORT-validator/commit/673c679b6bf3f4187cd5242c31a795bf8
- https://github.com/NICMx/FORT-validator/commit/eb68ebbaab50f3365aa51bbaa17cb862b
- https://github.com/NICMx/FORT-validator/releases/tag/1.5.2PatchRelease NotesThird Party Advisory
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
- https://github.com/NICMx/FORT-validator/commit/274dc14aed1eb9b3350029d1063578a6b
- https://github.com/NICMx/FORT-validator/commit/425e0f4037b4543fe8044ac96ca71d6d0
- https://github.com/NICMx/FORT-validator/commit/673c679b6bf3f4187cd5242c31a795bf8
- https://github.com/NICMx/FORT-validator/commit/eb68ebbaab50f3365aa51bbaa17cb862b
- https://github.com/NICMx/FORT-validator/releases/tag/1.5.2PatchRelease NotesThird Party Advisory
- https://www.debian.org/security/2021/dsa-5033Third Party Advisory
FAQ
What is CVE-2021-43114?
CVE-2021-43114 is a vulnerability with a CVSS score of 7.5 (HIGH). FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectivel...
How severe is CVE-2021-43114?
CVE-2021-43114 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-43114?
Check the references section above for vendor advisories and patch information. Affected products include: Fort Validator Project Fort Validator, Debian Debian Linux.