CVE-2024-56170
CVSS 3.1 Score 5.3 of 10 (medium)
Details
Published Dec 18, 2024
Updated: Dec 26, 2024
CWE ID 346
Summary
CVE-2024-56170 is a validation integrity issue affecting Fort's RPKI manifest handling before version 2.0.0. RPKI manifests are critical for ensuring the authenticity of routing information. They contain a manifestNumber and thisUpdate field, which determine a manifest's relevance. Fort's product, however, fails to compare the up-to-dateness of the most recently fetched manifest against the cached one, making it susceptible to a rollback to an outdated manifest. This vulnerability can result in the use of inaccurate or outdated route origin validation.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.