Nicmx maintains the Fort Validator, a focused cryptographic and RPKI validation tool that occupies a specialized but critical role in BGP security infrastructure, and its vulnerability profile skews toward serious outcomes with an elevated share reaching critical severity. The recurring weakness classes—including NULL-pointer dereferences, buffer overflows, improper certificate validation, and input-validation flaws—reflect the memory-safety and cryptographic-parsing demands intrinsic to a validator processing untrusted routing data and X.509 certificates at scale. Defenders relying on this tool for route origin validation should monitor vendor releases closely; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Nicmx over time
Signals from CVEs in this vendor scope (9 CVEs).
9 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-45237CRITICAL An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containin | Aug 24, 2024 | 9.8 | 28 | NO | NO |
CVE-2024-56375HIGH An integer underflow was discovered in Fort 1.6.3 and 1.6.4 before 1.6.5. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a Ma | Dec 22, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45239HIGH An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing | Aug 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45238HIGH An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containin | Aug 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45236HIGH An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a signed object containing an em | Aug 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45235HIGH An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) a resource certificate containin | Aug 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-45234HIGH An issue was discovered in Fort before 1.6.3. A malicious RPKI repository that descends from a (trusted) Trust Anchor can serve (via rsync or RRDP) an ROA or a Manifest containing | Aug 24, 2024 | 7.5 | 22 | NO | NO |
CVE-2024-56170MEDIUM A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI manifests are listings of relevant files that clients are supposed to verify. Assuming everythi | Dec 18, 2024 | 5.3 | 17 | NO | NO |
CVE-2024-56169MEDIUM A validation integrity issue was discovered in Fort through 1.6.4 before 2.0.0. RPKI Relying Parties (such as Fort) are supposed to maintain a backup cache of the remote RPKI data. | Dec 18, 2024 | 5.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (9 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Nicmx.
Media articles that mention a CVE ID that affects a product developed by Nicmx — matched by CVE ID, not by vendor name.