PT-2021-21737 · Octorpki · Octorpki

Job Snijders

·

Published

2021-09-07

·

Updated

2022-07-15

·

CVE-2021-3761

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions OctoRPKI versions prior to 1.3.0
Description Any CA issuer in the RPKI can trick OctoRPKI into emitting an invalid VRP "MaxLength" value, causing RTR sessions to terminate. An attacker can use this to disable RPKI Origin Validation in a victim network, for example AS 13335 - Cloudflare, prior to launching a BGP hijack which during normal operations would be rejected as "RPKI invalid". Additionally, in certain deployments RTR session flapping in and of itself also could cause BGP routing churn, causing availability issues.
Recommendations For OctoRPKI versions prior to 1.3.0, update to version 1.3.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the RTR sessions to minimize the risk of exploitation. Avoid using the MaxLength field in the VRP until the issue is resolved.

Fix

Improper Certificate Validation

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-3761
DSA-5041-1
GHSA-C8XP-8MF3-62H9
GO-2022-0246

Affected Products

Octorpki