PT-2019-2528 · Mikrotik · Routeros+1
Jacob Baines
·
Publicado
2019-04-10
·
Atualizado
2019-12-17
·
CVE-2019-3943
CVSS v3.1
8.1
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MikroTik RouterOS versions Stable 6.43.12 and below
MikroTik RouterOS versions Long-term 6.42.12 and below
MikroTik RouterOS versions Testing 6.44beta75 and below
Description
The issue is related to directory traversal errors in the restricted access directory path. An authenticated, remote attack can exploit this to read and write files outside of the sandbox directory (/rw/disk) via the HTTP or Winbox interfaces.
Recommendations
For MikroTik RouterOS versions Stable 6.43.12 and below, update to a version above 6.43.12 to resolve the issue.
For MikroTik RouterOS versions Long-term 6.42.12 and below, update to a version above 6.42.12 to resolve the issue.
For MikroTik RouterOS versions Testing 6.44beta75 and below, update to a version above 6.44beta75 to resolve the issue.
As a temporary workaround, consider restricting access to the HTTP and Winbox interfaces until a patch is available.
Exploit
Correção
Relative Path Traversal
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mikrotik Routeros
Routeros