CVE-2022-3616
OctoRPKI crash when maximum iterations number is reached
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Attackers can create long chains of CAs that would lead to OctoRPKI exceeding its max iterations parameter. In consequence it would cause the program to crash, preventing it from finishing the validation and leading to a denial of service. Credits to Donika Mirdita and Haya Shulman - Fraunhofer SIT, ATHENE, who discovered and reported this vulnerability.
Los atacantes pueden crear largas cadenas de CA que llevarían a OctoRPKI a exceder su parámetro máximo de iterations. En consecuencia provocaría que el programa colapsara, impidiendo que finalice la validación y provocando una Denegación de Servicio. Créditos a Donika Mirdita y Haya Shulman - Fraunhofer SIT, ATHENE, quienes descubrieron e informaron esta vulnerabilidad.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-10-20 CVE Reserved
- 2022-10-28 CVE Published
- 2024-05-20 EPSS Updated
- 2024-08-03 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-754: Improper Check for Unusual or Exceptional Conditions
- CWE-834: Excessive Iteration
CAPEC
- CAPEC-153: Input Data Manipulation
References (1)
URL | Tag | Source |
---|---|---|
https://github.com/cloudflare/cfrpki/security/advisories/GHSA-pmw9-567p-68pc | Third Party Advisory |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cloudflare Search vendor "Cloudflare" | Octorpki Search vendor "Cloudflare" for product "Octorpki" | < 1.4.4 Search vendor "Cloudflare" for product "Octorpki" and version " < 1.4.4" | - |
Affected
|