PT-2021-23746 · Unknown · Fort Validator

Published

2021-11-09

·

Updated

2024-10-15

·

CVE-2021-43114

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions FORT Validator versions prior to 1.5.2
Description The issue occurs when an RPKI CA publishes an X.509 EE certificate, causing FORT Validator to crash. This crash leads to RTR clients, such as BGP routers, losing access to the RPKI VRP data set, effectively disabling Route Origin Validation.
Recommendations For versions prior to 1.5.2, update to version 1.5.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the RPKI CA until the update is applied.

Fix

Related Identifiers

CVE-2021-43114
DSA-5033-1

Affected Products

Fort Validator