Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-pmjf-334r-5j9j

Опубликовано: 07 сент. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

EPSS

Процентиль: 92%
0.08542
Низкий

7.5 High

CVSS3

Дефекты

CWE-787

Связанные уязвимости

CVSS3: 7.5
nvd
больше 2 лет назад

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

CVSS3: 7.5
fstec
почти 3 года назад

Уязвимость веб-сервера JSProxy операционной системы RouterOS маршрутизаторов MikroTik, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 92%
0.08542
Низкий

7.5 High

CVSS3

Дефекты

CWE-787