PT-2017-18283 · Mikrotik · Mikrotik+1
Farazpajohan
+1
·
Published
2017-05-18
·
Updated
2019-10-03
·
CVE-2017-8338
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
MikroTik version 6.38.5
Description
A vulnerability could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500, which is used for L2TP over IPsec. This prevents the affected router from accepting new connections, causing all devices to be disconnected from the router and all logs to be removed automatically.
Recommendations
For MikroTik version 6.38.5, consider restricting access to port 500 to minimize the risk of exploitation. As a temporary workaround, limiting the number of incoming UDP packets on this port may help mitigate the issue until a patch is available.
Exploit
Fix
Resource Exhaustion
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mikrotik
Mikrotik Routeros