PT-2019-4067 · Mikrotik · Routeros+1

Published

2019-09-11

·

Updated

2021-12-09

·

CVE-2019-3977

CVSS v2.0

8.5

High

VectorAV:N/AC:L/Au:N/C:N/I:C/A:P
Name of the Vulnerable Software and Affected Versions RouterOS versions 6.45.6 and earlier RouterOS versions 6.44.5 and earlier
Description The issue is related to insufficient validation of upgrade packages when using the autoupgrade feature, allowing a remote attacker to trick the router into "upgrading" to an older version of RouterOS. This could lead to the reset of all system usernames and passwords, potentially giving the attacker unauthorized access to the system. The vulnerability is associated with the download of code without checking its integrity.
Recommendations For RouterOS versions 6.45.6 and earlier, consider disabling the autoupgrade feature until a patch is available to prevent potential exploitation. For RouterOS versions 6.44.5 and earlier, restrict access to the upgrade feature to minimize the risk of exploitation. Avoid using the autoupgrade feature in RouterOS until the issue is resolved.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-04628
CVE-2019-3977

Affected Products

Mikrotik Routeros
Routeros