PT-2021-21737 · Octorpki · Octorpki
Job Snijders
·
Published
2021-09-07
·
Updated
2022-07-15
·
CVE-2021-3761
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
OctoRPKI versions prior to 1.3.0
Description
Any CA issuer in the RPKI can trick OctoRPKI into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network, for example AS 13335 - Cloudflare, prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.
Recommendations
For OctoRPKI versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the RTR sessions to minimize the risk of exploitation. Avoid using the
MaxLength field in the VRP until the issue is resolved.Fix
Improper Certificate Validation
Memory Corruption
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Octorpki