CVE-2021-3761 is a high-severity vulnerability affecting OctoRPKI prior to version 1.3.0, and consequently Cloudflare and Debian systems utilizing it. An attacker can exploit this by crafting a malicious RPKI CA issuer, causing OctoRPKI to emit invalid VRP "MaxLength" values. This leads to RTR session termination, effectively disabling RPKI Origin Validation and potentially enabling BGP hijacks that would otherwise be rejected. The vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and high impact on availability. There is currently no public exploit code, no evidence of active exploitation, and minimal community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.3.0CPE matchmatch criteria | cpe:2.3:a:cloudflare:octorpki:*:*:*:*:*:*:*:* | ||
11.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.