Orta ÖNEM — Güvenlik Açığı

CVE-2024-54772 — An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stabl

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

Platform
MikroTik RouterOS
CVE Kaydı
CVE-2024-54772
CVSS Skoru
5.4/10
Yayın Tarihi
11 Şubat 2025
Okunma
2
Birincil kaynak: Kaynaktaki resmî duyuruyu inceleyin: nvd.nist.gov Kaynağa Git

Özet

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

Değerlendirme

  • CVE: CVE-2024-54772
  • CVSS taban puanı: 5.4
  • Vektör: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
  • Kaynak: NVD kaydı

Referanslar

Aksiyon

  • Etkilenen sistemleri envanterden doğrulayın
  • Üretici yamasını bakım penceresinde uygulayın
  • Yama uygulanana kadar erişimi ağ katmanında kısıtlayın
routeros *

MikroTik RouterOS — İlgili Duyurular

TÜMÜNÜ GÖR →