
Cloud Vulnerability DB
A community-led vulnerabilities database
An issue was discovered in NLnet Labs Routinator versions 0.1.0 through 0.7.1, identified as CVE-2020-17366. The vulnerability allows remote attackers to bypass intended access restrictions or cause a denial of service on dependent routing systems by strategically withholding RPKI Route Origin Authorisation '.roa' files or X509 Certificate Revocation List files from the RPKI relying party's view. This vulnerability was discovered and disclosed in August 2020 (NVD).
The vulnerability has a CVSS v3.1 base score of 7.4 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H. The issue stems from improper validation of missing files referenced in manifests, which could lead to incomplete or compromised validation of RPKI data. When a manifest references non-existing files or there are checksum mismatches between the manifest and ROA files, the system should consider the whole manifest invalid (GitHub Issue).
The exploitation of this vulnerability can result in severe operational issues in real networks. In a specific attack scenario, if certain ROA files are withheld, it could cause BGP announcements to be incorrectly marked as invalid, potentially leading to network downtime. For example, if an attacker strategically removes specific ROA files while leaving others, it could result in incomplete VRP (Validated ROA Payload) sets that incorrectly invalidate legitimate BGP announcements (GitHub Issue).
The vulnerability can be exploited by an attacker in a man-in-the-middle (MITM) position who can intercept and manipulate the rsync channel. The attacker could strategically withhold certain .roa files from the validator's view or corrupt files with garbage data, leading to incomplete or incorrect validation results (GitHub Issue).
The vulnerability was fixed in Routinator version 0.8.0. The update includes significant changes to validation rules following draft-ietf-sidrops-6486bis, where any invalid object mentioned on the manifest will lead to the issuing CA and all its objects being rejected. The fix also includes stricter CRL handling, requiring each CA to have exactly one CRL that matches the manifest's EE certificate (Release Notes).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."