CVE-2024-45236: Input Validation
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an empty signedAttributes field. Fort accesses the set's elements without sanitizing it first. Because Fort is an RPKI Relying Party, a crash can lead to Route Origin Validation unavailability, which can lead to compromised routing.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45236?
CVE-2024-45236 has been classified as a moderate severity vulnerability.
How do I fix CVE-2024-45236?
To fix CVE-2024-45236, upgrade Fort Validator to version 1.6.3 or later.
What product is affected by CVE-2024-45236?
CVE-2024-45236 affects the NICMx FORT Validator software versions prior to 1.6.3.
What are the potential consequences of CVE-2024-45236?
CVE-2024-45236 could allow an attacker to exploit the vulnerability by serving a malicious RPKI repository.
Is CVE-2024-45236 related to RPKI?
Yes, CVE-2024-45236 specifically relates to a vulnerability in an RPKI relying software component.