CVE-2024-45237
published 2024-08-24CVE-2024-45237: An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource…
PriorityP347critical9.8CVSS 3.1
AVNACLPRNUINSUCHIHAH
EPSS
0.36%
28.4th percentile
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fort-validator | < fort-validator 1.5.4-1+deb12u1 (bookworm) | fort-validator 1.5.4-1+deb12u1 (bookworm) |
| nicmx | fort-validator | < 1.6.3 | 1.6.3 |
| nicmx | fort-validator | >= 0 < 1.5.3-1~deb11u2 | 1.5.3-1~deb11u2 |
| nicmx | fort-validator | >= 0 < 1.5.4-1+deb12u1 | 1.5.4-1+deb12u1 |
| nicmx | fort-validator | >= 0 < 1.6.3-1 | 1.6.3-1 |
| nicmx | fort-validator | >= 0 < 1.6.3-1 | 1.6.3-1 |
| nicmx | fort-validator | >= 0 < 1.5.3-1ubuntu0.1 | 1.5.3-1ubuntu0.1 |
| nicmx | fort-validator | >= 0 < 1.2.0-1ubuntu0.1~esm1 | 1.2.0-1ubuntu0.1~esm1 |
| nicmx | fort-validator | >= 0 < 1.6.1-1ubuntu0.1~esm2 | 1.6.1-1ubuntu0.1~esm2 |
| tianocore | edk2 | >= 0 < 2022.02-3ubuntu0.22.04.5 | 2022.02-3ubuntu0.22.04.5 |
| tianocore | edk2 | >= 0 < 2022.02-3ubuntu0.22.04.4 | 2022.02-3ubuntu0.22.04.4 |
| tianocore | edk2 | >= 0 < 2024.02-2ubuntu0.7 | 2024.02-2ubuntu0.7 |
| tianocore | edk2 | >= 0 < 2024.02-2ubuntu0.6 | 2024.02-2ubuntu0.6 |
CVSS provenance
nvdv3.19.8CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
osv9.8CRITICAL
vendor_debian9.8CRITICAL
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FORT Validator vulnerabilities
vendor_ubuntu·2025-10-08·CVSS 7.5
CVE-2024-45236 [HIGH] FORT Validator vulnerabilities
Title: FORT Validator vulnerabilities
Summary: Several security issues were fixed in FORT Validator.
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers wh
Debian
CVE-2024-45237: fort-validator - An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that d...
vendor_debian·2024·CVSS 9.8
CVE-2024-45237 [CRITICAL] CVE-2024-45237: fort-validator - An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that d...
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.
Scope: local
bookworm: resolved (fixed in 1.5.4-1+deb12u1)
bullseye: resolved (fixed in 1.5.3-1~deb11u2)
forky: resolved (fixed in 1.6.3-1)
sid: resolved (fixed in 1.6.3-1)
trixie: resolved (fixed in 1.6.3-1)
OSV
edk2 regression
osv·2025-11-28·CVSS 7.4
CVE-2023-45236 edk2 regression
edk2 regression
USN-7894-1 fixed vulnerabilities in EDK II. The update introduced a
regression in the UEFI network boot. This update reverts the corresponding
fixes for CVE-2023-45236 and CVE-2023-45237 pending further investigation.
We apologize for the inconvenience.
Original advisory details:
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that
OSV
edk2 vulnerabilities
osv·2025-11-26·CVSS 7.4
CVE-2023-45236 edk2 vulnerabilities
edk2 vulnerabilities
It was discovered that EDK II was susceptible to a predictable TCP Initial
Sequence Number. An attacker could possibly use this issue to gain
unauthorized access. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2023-45236, CVE-2023-45237)
It was discovered that EDK II incorrectly handled S3 sleep. An attacker
could possibly use this issue to cause a denial of service. This issue only
affected Ubuntu 22.04 LTS, and Ubuntu 24.04 LTS. (CVE-2024-1298)
It was discovered that the EDK II PE/COFF loader incorrectly handled
certain memory operations. An attacker could possibly use this issue to
cause a denial of service, obtain sensitive information, or execute
arbitrary code. This issue only affected Ubuntu 22.04 LTS, and Ubuntu
24.04 LTS. (CVE-2024-38
OSV
fort-validator vulnerabilities
osv·2025-10-08·CVSS 7.5
CVE-2024-45234 [HIGH] fort-validator vulnerabilities
fort-validator vulnerabilities
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers when fetching RPKI repository data. A remote attacker could
possibly use
GHSA
GHSA-wpp2-87q7-h53v: An issue was discovered in Fort before 1
ghsa_unreviewed·2024-08-25
CVE-2024-45237 [CRITICAL] CWE-120 GHSA-wpp2-87q7-h53v: An issue was discovered in Fort before 1
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.
OSV
CVE-2024-45237: An issue was discovered in Fort before 1
osv·2024-08-24·CVSS 9.8
CVE-2024-45237 [CRITICAL] CVE-2024-45237: An issue was discovered in Fort before 1
An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containing a Key Usage extension composed of more than two bytes of data. Fort writes this string into a 2-byte buffer without properly sanitizing its length, leading to a buffer overflow.
No detection rules found.
No public exploits indexed.
arXiv
Poster: From Fort to Foe: The Threat of RCE in RPKI
arxiv_cs_cr·2024-11-25·CVSS 9.8
[CRITICAL] Poster: From Fort to Foe: The Threat of RCE in RPKI
Poster: From Fort to Foe: The Threat of RCE in RPKI
In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software. We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploit on a large scale, allows compromise of RPKI validation integrity, and enables a powerful vector for additional attacks on other critical components of the network, like the border routers.
We analyze the vulnerability exposing to this RCE and identify indications that the discovered vulnerability could constitute an intentional backdoor to compromise
arXiv
Poster: From Fort to Foe: The Threat of RCE in RPKI
arxiv_fulltext·2024-11-25·CVSS 9.8
[CRITICAL] Poster: From Fort to Foe: The Threat of RCE in RPKI
Poster: From Fort to Foe: The Threat of RCE in RPKI
Oliver Jacobsen
ATHENE
Darmstadt
Germany
Goethe-Universität Frankfurt
FrankfurtGermany
Haya Schulmann
ATHENE
Darmstadt
Germany
Goethe-Universität Frankfurt
FrankfurtGermany
Niklas Vogel
ATHENE
Darmstadt
Germany
Goethe-Universität Frankfurt
FrankfurtGermany
Michael Waidner
ATHENE
Darmstadt
Germany
TU Darmstadt
Darmstadt
Germany
## Abstract
In this work, we present a novel severe buffer-overflow vulnerability in the RPKI validator Fort, that allows an attacker to achieve Remote Code Execution (RCE) on the machine running the software.
We discuss the unique impact of this RCE on networks that use RPKI, illustrating that RCE vulnerabilities are especially severe in the context of RPKI. The design of RPKI makes RCE easy to exploi
2024-08-24
Published