CVE-2024-45239

CVSS 3.1 Score 7.5 of 10 (high)

Details

Published Aug 24, 2024
Updated: Aug 27, 2024
CWE ID 476

Summary

CVE-2024-45239 affects Fort versions prior to 1.6.3, where a malicious RPKI repository can exploit a null eContent field, leading to the dereferencing of a pointer without prior sanitization. This vulnerability can cause the Fort RPKI Relying Party to crash, resulting in Route Origin Validation becoming unavailable and potentially compromising routing integrity. Organizations using affected Fort products are at risk, as the availability impact is rated high with a base score of 7.5 on the CVSS scale. To remediate this issue, upgrading to version 1.6.3 or later is essential to mitigate the vulnerability's effects. The attack vector is categorized as network-based with low complexity and does not require user interaction or elevated privileges for exploitation.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share