CVE-2019-3979

Severity CVSS v4.0:
Pending analysis
Type:
CWE-345 Insufficient Verification of Data Authenticity
Publication date:
29/10/2019
Last modified:
21/07/2021

Description

RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* 6.44.5 (including)
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* 6.45.6 (including)


References to Advisories, Solutions, and Tools