PT-2019-3895 · Mikrotik · Routeros+1

Jacob Baines

·

Publicado

2019-10-28

·

Atualizado

2021-07-21

·

CVE-2019-3979

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:N/I:C/A:N
Name of the Vulnerable Software and Affected Versions RouterOS versions 6.45.6 and below RouterOS version 6.44.5 Long-term and below
Description The issue allows a remote attacker to poison the router's DNS cache via malicious responses with additional and untrue records. This is due to the router adding all A records to its DNS cache even when the records are unrelated to the domain that was queried. The vulnerability exists because of insufficient input validation, which can allow an attacker to cause damage to the integrity of the data in the DNS system.
Recommendations For RouterOS versions 6.45.6 and below, update to a version above 6.45.6 to resolve the issue. For RouterOS version 6.44.5 Long-term and below, update to a version above 6.44.5 to resolve the issue. As a temporary workaround, consider restricting access to the winbox dns request to minimize the risk of exploitation. Avoid using the vulnerable DNS cache functionality until the issue is resolved. Restrict access to the TCP port 8291 (Winbox) to prevent remote attackers from exploiting the vulnerability.

Correção

Insufficient Verification of Data Authenticity

RCE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2019-04288
CVE-2019-3979

Produtos afetados

Mikrotik Routeros
Routeros