Access Control Vulnerability in NLnet Labs Routinator
CVE-2020-17366

7.4HIGH

Key Information:

Vendor

Nlnetlabs

Vendor
CVE Published:
5 August 2020

What is CVE-2020-17366?

An issue was identified in NLnet Labs Routinator versions 0.1.0 to 0.7.1 that permits remote attackers to circumvent established access restrictions. This loophole can be exploited to induce a denial of service in routing systems linked to RPKI by withholding critical RPKI Route Origin Authorization (.roa) files or X509 Certificate Revocation List files from the view of the RPKI relying party. This vulnerability can potentially disrupt the integrity and availability of routing services.

References

CVSS V3.1

Score:
7.4
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.