CVE-2023-39915
NLnet Labs' Routinator up to and including version 0.12.1 may crash when trying to parse certain malformed RPKI objects. This is due to insufficient input checking in the bcder library covered by CVE-2023-39914.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS probability
- 0.35%
- CWE
- CWE-232, CWE-240
- Published
- 2023-09-13
- Last modified
- 2026-03-13
Affected products
- NLnet Labs Routinator
- NLnet Labs Routinator
Weakness type
Related vulnerabilities
- CVE-2026-21689 — iccDEV has Type Confusion in CIccProfileXml::ParseBasic() at IccXML/IccLibXML/IccProfileXml.cpp
- CVE-2025-20314 — A vulnerability in Cisco IOS XE Software could allow an authenticated, local attacker with level-15...
- CVE-2025-40775 — DNS message with invalid TSIG causes an assertion failure
- CVE-2025-20192 — A vulnerability in the Internet Key Exchange version 1 (IKEv1) implementation of Cisco IOS XE...
- CVE-2023-39914 — BER/CER/DER decoder panics on invalid input
- CVE-2023-36848 — Junos OS: MX Series: The FPC will crash on receiving a malformed CFM packet
- CVE-2023-2968 — Undefined variable usage in npm package "proxy" leads to remote denial of service
- CVE-2022-22213 — Junos OS and Junos OS Evolved: Denial of Service (DoS) vulnerability in RPD upon receipt of specific BGP update