CVE-2021-43114

FORT Validator versions prior to 1.5.2 will crash if an RPKI CA publishes an X.509 EE certificate. This will lead to RTR clients such as BGP routers to lose access to the RPKI VRP data set, effectively disabling Route Origin Validation.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Affected Products (NVD)
VendorProductVersion
fort_validator_projectfort_validator
𝑥
< 1.5.2
debiandebian_linux
11.0
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
fort-validator
bookworm
1.5.4-1
fixed
bullseye
1.5.3-1~deb11u1
fixed
bullseye (security)
1.5.3-1~deb11u1
fixed
sid
1.6.4+20240930-1
fixed
trixie
1.6.4+20240930-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
fort-validator
focal
needs-triage
hirsute
ignored
impish
ignored
jammy
not-affected
kinetic
not-affected
lunar
not-affected
mantic
not-affected
noble
not-affected
trusty
ignored
xenial
ignored