7.5
CVSSv3

CVE-2021-3909

Published: 11/11/2021 Updated: 04/04/2022
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

OctoRPKI does not limit the length of a connection, allowing for a slowloris DOS attack to take place which makes OctoRPKI wait forever. Specifically, the repository that OctoRPKI sends HTTP requests to will keep the connection open for a day before a response is returned, but does keep drip feeding new bytes to keep the connection alive.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

cloudflare octorpki

debian debian linux 11.0

Vendor Advisories

Multiple vulnerabilities were discovered in Cloudflare's RPKI validator, which could result in denial of service or path traversal For the stable distribution (bullseye), these problems have been fixed in version 142-1~deb11u1 We recommend that you upgrade your cfrpki packages For the detailed security status of cfrpki please refer to its secu ...
Multiple vulnerabilities were discovered in the FORT RPKI validator, which could result in denial of service or path traversal For the stable distribution (bullseye), these problems have been fixed in version 153-1~deb11u1 We recommend that you upgrade your fort-validator packages For the detailed security status of fort-validator please refer ...