CVE-2020-16162: Ripe Rpki Validator 3

High severity, CVSS 7.5. EPSS: 0.7% chance of exploitation in the next 30 days.

An issue was discovered in RIPE NCC RPKI Validator 3.x through 3.1-2020.07.06.14.28. Missing validation checks on CRL presence or CRL staleness in the X509-based RPKI certificate-tree validation procedure allow remote attackers to bypass intended access restrictions by using revoked certificates. NOTE: there may be counterarguments related to backwards compatibility

Affected products

  • Ripe Rpki Validator 3: from 3.0, up to and including 3.1-2020.07.06.14.28

Published 2020-07-30. Last modified 2026-06-17.