High SEVERITY — Vulnerability

CVE-2023-30800 — The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue.

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

Platform
MikroTik RouterOS
CVE Record
CVE-2023-30800
CVSS Score
7.5/10
Published
07 September 2023
Views
3
Primary source: Review the official advisory at nvd.nist.gov Kaynağa Git

Summary

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

Assessment

  • CVE: CVE-2023-30800
  • CVSS base score: 7.5
  • Vector: CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H
  • Source: NVD entry

References

Actions

  • Verify affected systems in your inventory
  • Apply the vendor's patch during a maintenance window
  • Restrict access at the network layer until the patch is applied
routeros *

MikroTik RouterOS — Related Advisories

VIEW ALL →