CVE-2023-39915 Vulnerability Details

  /     /     /  

CVE-2023-39915 Metadata Quick Info

CVE Published: 13/09/2023 | CVE Updated: 12/09/2024 | CVE Year: 2023
Source: NLnet Labs | Vendor: NLnet Labs | Product: Routinator
Status : PUBLISHED

CVE-2023-39915 Description

NLnet Labs\' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-232
CWE Name: CWE-232: Improper Handling of Undefined Values
Source: NLnet Labs

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).