CVE Vulnerabilities

CVE-2020-17366

Improper Certificate Validation

Published: Aug 05, 2020 | Modified: Jan 27, 2023
CVSS 3.x
7.4
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H
CVSS 2.x
5.8 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

An issue was discovered in NLnet Labs Routinator 0.1.0 through 0.7.1. It allows remote attackers to bypass intended access restrictions or to cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation .roa files or X509 Certificate Revocation List files from the RPKI relying partys view.

Weakness

The product does not validate, or incorrectly validates, a certificate.

Affected Software

Name Vendor Start Version End Version
Routinator Nlnetlabs 0.1.0 (including) 0.7.1 (including)

Potential Mitigations

References