PT-2015-5726 · Mikrotik · Routeros+1

Mohamed Abdelbaset Elnoby

+1

·

Publicado

2015-03-19

·

Atualizado

2015-09-24

·

CVE-2015-2350

CVSS v2.0

6.8

Média

VetorAV:N/AC:M/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions prior to 5.0
Description A cross-site request forgery issue allows remote attackers to hijack administrator authentication for requests that change the administrator password. This is achieved via a request in the status page to "/cfg" API endpoint, specifically targeting the password variable.
Recommendations For versions prior to 5.0, as a temporary workaround, consider restricting access to the "/cfg" API endpoint until a patch is available. Avoid using the password variable in the affected API endpoint until the issue is resolved.

Exploit

Correção

CSRF

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2015-2350

Produtos afetados

Mikrotik Routeros
Routeros