CVE-2019-3978

Severity CVSS v4.0:
Pending analysis
Type:
CWE-306 Missing Authentication for Critical Function
Publication date:
29/10/2019
Last modified:
01/11/2019

Description

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below allow remote unauthenticated attackers to trigger DNS queries via port 8291. The queries are sent from the router to a server of the attacker's choice. The DNS responses are cached by the router, potentially resulting in cache poisoning

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* 6.44.5 (including)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* 6.45.6 (including)