
Cloud Vulnerability DB
A community-led vulnerabilities database
A high-severity vulnerability was discovered in RIPE NCC RPKI Validator 3.x through version 3.1-2020.07.06.14.28. The vulnerability affects the RPKI manifest validation process when objects on the manifest are hidden or expired objects are replayed. This security issue was published on November 3, 2020, and primarily impacts the RPKI (Resource Public Key Infrastructure) validation system (GitHub Advisory).
The vulnerability is tracked as GHSA-q76j-58cx-wp5v and has been assigned a CVSS 3.1 Base Score of 7.4 (HIGH) with the vector string CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:H. The issue is related to improper certificate validation (CWE-295) and involves the validation methods specified in RFC 6486bis (NVD).
When successfully exploited, this vulnerability could prevent new ROAs (Route Origin Authorisations) from being received or allow selective hiding of ROAs, causing routes to become INVALID. This could potentially lead to significant disruptions in routing systems and bypass of intended access restrictions (GitHub Advisory).
To exploit this vulnerability, an attacker would need to perform a man-in-the-middle attack either on the TLS connection between the validator and an RRDP repository or against a rsync-only repository (GitHub Advisory).
The vulnerability was patched in version 3.2-2020.10.28.23.06. The update addresses the vulnerability by implementing validation methods from RFC 6486bis and enabling strict validation by default (GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."