Yüksek ÖNEM — Güvenlik Açığı

CVE-2024-54952 — MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability.

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.

Platform
MikroTik RouterOS
CVE Kaydı
CVE-2024-54952
CVSS Skoru
7.5/10
Yayın Tarihi
29 Mayıs 2025
Okunma
2
Birincil kaynak: Kaynaktaki resmî duyuruyu inceleyin: nvd.nist.gov Kaynağa Git

Özet

MikroTik RouterOS 6.40.5, the SMB service contains a memory corruption vulnerability. Remote, unauthenticated attackers can exploit this issue by sending specially crafted packets, triggering a null pointer dereference. This leads to a Remote Denial of Service (DoS), rendering the SMB service unavailable.

Değerlendirme

  • CVE: CVE-2024-54952
  • CVSS taban puanı: 7.5
  • Vektör: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
  • Kaynak: NVD kaydı

Referanslar

Aksiyon

  • Etkilenen sistemleri envanterden doğrulayın
  • Üretici yamasını bakım penceresinde uygulayın
  • Yama uygulanana kadar erişimi ağ katmanında kısıtlayın
routeros 6.40.5

MikroTik RouterOS — İlgili Duyurular

TÜMÜNÜ GÖR →