Yüksek ÖNEM — Güvenlik Açığı

CVE-2023-30800 — The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue.

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

Platform
MikroTik RouterOS
CVE Kaydı
CVE-2023-30800
CVSS Skoru
7.5/10
Yayın Tarihi
07 Eylül 2023
Okunma
2
Birincil kaynak: Kaynaktaki resmî duyuruyu inceleyin: nvd.nist.gov Kaynağa Git

Özet

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

Değerlendirme

  • CVE: CVE-2023-30800
  • CVSS taban puanı: 7.5
  • Vektör: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Kaynak: NVD kaydı

Referanslar

Aksiyon

  • Etkilenen sistemleri envanterden doğrulayın
  • Üretici yamasını bakım penceresinde uygulayın
  • Yama uygulanana kadar erişimi ağ katmanında kısıtlayın
routeros *

MikroTik RouterOS — İlgili Duyurular

TÜMÜNÜ GÖR →