PT-2019-4066 · Mikrotik · Routeros+1
Publicado
2019-09-11
·
Atualizado
2021-11-03
·
CVE-2019-3976
CVSS v3.1
8.8
Alta
| Vetor | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RouterOS versions 6.45.6 and earlier
RouterOS versions 6.44.5 and earlier
Description
The issue is related to an arbitrary directory creation vulnerability via the upgrade package's name field. If an authenticated user installs a malicious package, a directory could be created and the developer shell could be enabled. This vulnerability is also related to the implementation of the .NPK file processing mechanism in RouterOS, which is associated with bypassing relative paths. Exploitation of the vulnerability may allow a remote attacker to create arbitrary directories and execute arbitrary shell code using a malicious update package.
Recommendations
For RouterOS versions 6.45.6 and earlier, consider disabling the package installation feature until a patch is available.
For RouterOS versions 6.44.5 and earlier, restrict access to the upgrade package's name field to minimize the risk of exploitation.
As a temporary workaround, consider disabling the developer shell until a patch is available.
Correção
Relative Path Traversal
RCE
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Mikrotik Routeros
Routeros