National Research Center for Applied Cybersecurity ATHENE: Severe Vulnerabilities Discovered in Software to Protect Internet Routing
12.4.2024 08:49:14 CEST | news aktuell GmbH | Press release
A research team from the National Research Center for Applied Cybersecurity ATHENE led by Prof. Dr. Haya Schulmann has uncovered 18 vulnerabilities in crucial software components of Resource Public Key Infrastructure (RPKI). RPKI is an Internet standard meant to protect Internet traffic from being hijacked by hackers. By now, all affected vendors provided patches for their products. The vulnerabilities could have had devastating consequences: Internet hijacks have already been exploited, e.g., for phishing passwords and other sensitive information, tricking certificate authorities into issuing fraudulent Web certificates, stealing cryptocurrency, distributing malware, and poisoning caches of DNS servers.

Frankfurt and Darmstadt, April 2024
The ATHENE team consisting of Prof. Dr. Haya Schulmann and Niklas Vogel, both from Goethe University of Frankfurt, Donika Mirdita from TU Darmstadt, and Prof. Dr. Michael Waidner from TU Darmstadt and Fraunhofer SIT uncovered and disclosed 18 vulnerabilities. The National Vulnerability Database (NVD), operated by the US National Institute of Standards and Technology (NIST), assigned five Common Vulnerabilities and Exposures (CVE) entries to these vulnerabilities, some critical with a score of 9.3 out of 10. The team used a testing tool, CURE, which they developed specifically for this project and which ATHENE makes available free of charge to all developers of RPKI software. The researchers found vulnerabilities in all popular implementations of the validator component of RPKI. They range between crashes, violation of standard behavior, and even severe bugs that allow a network adversary to completely take over an RPKI certificate hierarchy in order to inject its own trust anchor – effectively being able to forge authentic and valid yet bogus routing information (i.e., BGP announcements). It is unknown whether any of the vulnerabilities were already exploited by hackers in the wild.
RPKI is a relatively new standard. Today, about 50% of the Internet’s network prefixes are covered by RPKI certificates, and 37.8% of all Internet domains validate RPKI certificates. In particular, many large providers and operators support RPKI, e.g., Amazon Web Services, Cogent, Deutsche Telekom, Level 3, and Zayo.
The research work was carried out in the ATHENE research area Analytic Based Cybersecurity (ABC) (more information at https://abc.athene-center.de/en/ ) and appeared at the 2024 Network and Distributed System Security (NDSS) Symposium in San Diego, California, USA. The research paper can be downloaded from https://www.ndss-symposium.org/ndss-paper/the-cure-to-vulnerabilities-in-rpki-validation/. The testing tool CURE developed and used by the researchers to uncover the vulnerabilities can be downloaded from https://github.com/rp-cure/rp-cure.
The National Research Center for Applied Cybersecurity ATHENE is a research center of the Fraunhofer Society that brings together the Fraunhofer Institutes for Secure Information Technology (SIT) and for Computer Graphics Research (IGD), Technische Universität Darmstadt, Goethe-Universität Frankfurt am Main, and Darmstadt University of Applied Sciences. With more than 600 scientists, ATHENE is Europe's most prominent cybersecurity research center and Germany’s leading scientific research institution in this domain. ATHENE is supported by the German Federal Ministry of Education and Research (BMBF) and the Hessian Ministry for Higher Education, Research, Science and the Arts (HMWK). Further information about ATHENE can be found at https://www.athene-center.de/en/.
Press Contact: Mrs. Cornelia Reitz, cornelia.reitz@athene-center.de
Subscribe to releases from news aktuell GmbH
Subscribe to all the latest releases from news aktuell GmbH by registering your e-mail address below. You can unsubscribe at any time.
Latest releases from news aktuell GmbH
HEIDELBERG systematically pressing ahead with strategic development – solid start to FY 2026/202719.8.2026 09:02:17 CEST | Press release
Taking over manroland sheetfed lifecycle business and POLAR production operations strengthens core business ONBERG pursuing partnership with Skyeton in European defense sector Move into production of sodium-ion battery storage systems taps into new potential First-quarter incoming orders lay solid foundation for further business development Sales and EBITDA margin at start of year in line with expectations Forecast for financial year 2026/2027 confirmed
Polarise secures further debt financing to expand its European AI cloud platform18.8.2026 11:47:20 CEST | Press release
Düsseldorf, 18. August 2026 – Polarise Holding GmbH (“Polarise”), a European provider of sovereign AI cloud solutions, has secured a debt financing partnership with SWI Stoneweg Icona Group (“SWI Group”) to accelerate the expansion of its European AI cloud platform. The financing of up to a high double-digit million-euro amount strengthens Polarise’s funding base for the continued execution of its growth strategy. As part of the new financing structure, Polarise and SWI Group have agreed to transition the previously announced majority equity investment agreement into a debt financing arrangement. Michel Boutouil, CEO of Polarise, said: “Our growth strategy is aimed at building Europe’s AI infrastructure of the future – with sustainable, highly efficient AI Factories and sovereign AI compute for businesses. We are executing this strategy with significant momentum and strong partners. Polarise develops and operates AI data centres – so-called AI Factories – in Germany and across Europe.
Central Council calls for prevention through education and awareness-raising3.8.2026 09:19:17 CEST | Press release
Commemorative event to mark the European Holocaust Remembrance Day for Sinti and Roma on 2 August 2026 in Auschwitz-Birkenau
CHRIST chooses fulfillmenttools and commercetools for a future-proof commerce architecture31.7.2026 12:47:56 CEST | Press release
Cologne – CHRIST Juweliere und Uhrmacher, one of Europe's most renowned jewelry retailers, is partnering with fulfillmenttools to transform the way it manages and orchestrates orders across its retail network. CHRIST is implementing the Agentic Order Management System (OMS) – as part of a broader transformation in which the retailer is building a modular, future-proof commerce architecture powered by commercetools Sphere, the autonomous commerce platform. The new system landscape spans stores and digital channels across Germany, Austria and the Netherlands. Breaking free from monolithic constraints For internationally operating retailers, the ability to respond flexibly and quickly to customer demand is a key success factor. This is especially true in the jewellery trade, which is shaped by specific requirements: high-value products, complex inventory structures, and customers who expect a first-class, seamless shopping experience at every touchpoint. CHRIST has built a strong operatio
Bikeleasing Group announces strategic investment in New Zealand’s leading bike leasing company Workride / Next strategic step in cross-continental expansion29.7.2026 14:18:02 CEST | Press release
The Bikeleasing Group announces strategic investment in Workride, New Zealand’s market leader for company bike leasing as an employee benefit. Around 2,000 New Zealand employers already use Workride’s offering. The investment extends the Bikeleasing Group’s international presence and marks its next cross-continental step in its growth trajectory.
In our pressroom you can read all our latest releases, find our press contacts, images, documents and other relevant information about us.
Visit our pressroom