CVE-2023-0158 - CVE House
Back to Database
Status published Unknown CVE-2023-0158

Triggered crash on direct RRDP access

Vulnerability Description

NLnet Labs Krill supports direct access to the RRDP repository content through its built-in web server at the "/rrdp" endpoint. Prior to 0.12.1 a direct query for any existing directory under "/rrdp/", rather than an RRDP file such as "/rrdp/notification.xml" as would be expected, causes Krill to crash. If the built-in "/rrdp" endpoint is exposed directly to the internet, then malicious remote parties can cause the publication server to crash. The repository content is not affected by this, but the availability of the server and repository can cause issues if this attack is persistent and is not mitigated.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-0158

Credits & Attribution

The following person or organization is credited with identifying this vulnerability, as recorded in the NVD database:

  • We would like to thank user KittensAreDaBest on GitHub for the discovery and disclosure.

Affected Vendor

Affected Software

Krill
Vulnerable Versions:
unspecified

Timeline

Official Publish: January 17th, 2023
Last Modified: April 4th, 2025
Added to House: July 22nd, 2026

CVSS Vectors

No vector data available

Weaknesses (CWE)