CVE-2024-48943
published 2025-10-08CVE-2024-48943: Title: FORT Validator vulnerabilities Summary: Several security issues were fixed in FORT Validator. Niklas Vogel and Haya Schulmann discovered that FORT…
high7.5
Title: FORT Validator vulnerabilities
Summary: Several security issues were fixed in FORT Validator.
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers when fetching RPKI repository data. A remote attacker could
possibly use this issue to cause FORT Validator to consume excessive
resources, resulting in a denial of service. (CVE-2024-48943)
Instructions: After a standard system update you need to restart FORT Validator to make
all the necessary changes.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | fort-validator | < fort-validator 1.5.4-1+deb12u1 (bookworm) | fort-validator 1.5.4-1+deb12u1 (bookworm) |
| nicmx | fort-validator | >= 0 < 1.5.3-1ubuntu0.1 | 1.5.3-1ubuntu0.1 |
| nicmx | fort-validator | >= 0 < 1.2.0-1ubuntu0.1~esm1 | 1.2.0-1ubuntu0.1~esm1 |
| nicmx | fort-validator | >= 0 < 1.6.1-1ubuntu0.1~esm2 | 1.6.1-1ubuntu0.1~esm2 |
CVSS provenance
osv7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
FORT Validator vulnerabilities
vendor_ubuntu·2025-10-08·CVSS 7.5
CVE-2024-45236 [HIGH] FORT Validator vulnerabilities
Title: FORT Validator vulnerabilities
Summary: Several security issues were fixed in FORT Validator.
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers wh
Debian
CVE-2024-48943: fort-validator
vendor_debian·2024
CVE-2024-48943 CVE-2024-48943: fort-validator
bookworm: resolved (fixed in 1.5.4-1+deb12u1)
bullseye: resolved (fixed in 1.5.3-1~deb11u2)
forky: resolved (fixed in 1.6.4-1)
sid: resolved (fixed in 1.6.4-1)
trixie: resolved (fixed in 1.6.4-1)
OSV
fort-validator vulnerabilities
osv·2025-10-08·CVSS 7.5
CVE-2024-45234 [HIGH] fort-validator vulnerabilities
fort-validator vulnerabilities
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing certain RPKI repository data.
A remote attacker could possibly use this issue to cause FORT Validator to
crash, resulting in a denial of service. (CVE-2024-45234, CVE-2024-45235,
CVE-2024-45236, CVE-2024-45238, CVE-2024-45239)
Niklas Vogel and Haya Schulmann discovered that FORT Validator did not
perform proper input validation when parsing resource certificates. A
remote attacker could possibly use this issue to cause a denial of service
or execute arbitrary code. (CVE-2024-45237)
Koen van Hove discovered that FORT Validator did not limit the duration of
data transfers when fetching RPKI repository data. A remote attacker could
possibly use
OSV
CVE-2024-48943: A malicious RPKI rsync repository can prevent Fort from finishing its validation run by drip-feeding its content
osv·2025-01-10
CVE-2024-48943 CVE-2024-48943: A malicious RPKI rsync repository can prevent Fort from finishing its validation run by drip-feeding its content
A malicious RPKI rsync repository can prevent Fort from finishing its validation run by drip-feeding its content.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-10-08
Published