Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-hxg2-8cqf-77j7

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.

EPSS

Процентиль: 45%
0.00223
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-345

Связанные уязвимости

CVSS3: 7.5
nvd
больше 6 лет назад

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.

CVSS3: 7.5
fstec
больше 6 лет назад

Уязвимость операционной системы RouterOS, существующая из-за недостаточной проверки входных данных, позволяющая нарушителю вызвать повреждение целостности данных в системе DNS

EPSS

Процентиль: 45%
0.00223
Низкий

7.5 High

CVSS3

Дефекты

CWE-20
CWE-345