Описание
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
Ссылки
- ExploitMitigationThird Party Advisory
- ExploitMitigationThird Party Advisory
- Broken LinkExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- Vendor Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitMitigationThird Party Advisory
- ExploitMitigationThird Party Advisory
- Broken LinkExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- US Government Resource
Уязвимые конфигурации
Конфигурация 1Версия до 6.42 (включая)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
EPSS
Процентиль: 100%
0.93645
Критический
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22
CWE-22
Связанные уязвимости
CVSS3: 9.1
github
больше 3 лет назад
MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.
CVSS3: 8.6
fstec
почти 8 лет назад
Уязвимость компонента Winbox операционной системы RouterOS маршрутизаторов MikroTik, позволяющая нарушителю обойти процедуру аутентификации
EPSS
Процентиль: 100%
0.93645
Критический
9.1 Critical
CVSS3
6.4 Medium
CVSS2
Дефекты
CWE-22
CWE-22