HIGH🇵🇱 Wersja polska

CVE-2022-3029

CVSS 7.5v3.1pub. 2022-09-13upd. 2024-11-21

In NLnet Labs Routinator 0.9.0 up to and including 0.11.2, due to a mistake in error handling, data in RRDP snapshot and delta files that isn’t correctly base 64 encoded is treated as a fatal error and causes Routinator to exit. Worst case impact of this vulnerability is denial of service for the RPKI data that Routinator provides to routers. This may stop your network from validating route origins based on RPKI data. This vulnerability does not allow an attacker to manipulate RPKI data.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Nlnetlabs Routinator

    APP
    Nlnetlabs
    0.9.0 – 0.11.2
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
DoS
CWE
References

Related vulnerabilities

CVE-2023-39916CRITICAL9.3PL ✓same product

Path traversal w NLnet Labs Routinator — zapis odpowiedzi RRDP poza dozwolonym katalogiem

CVE-2026-49233HIGH8.3same product

Routinator does not properly check the module component of rsync URIs, which are used to create the file syste...

CVE-2026-49234HIGH8.2same product

When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endp...

CVE-2026-49235HIGH8.7same product

When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator c...

CVE-2024-1622HIGH7.5same product

Due to a mistake in error checking, Routinator will terminate when an incoming RTR connection is reset by the ...