CVE-2019-3979
Severity CVSS v4.0:
Pending analysis
Type:
CWE-345
Insufficient Verification of Data Authenticity
Publication date:
29/10/2019
Last modified:
21/07/2021
Description
RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below are vulnerable to a DNS unrelated data attack. The router adds all A records to its DNS cache even when the records are unrelated to the domain that was queried. Therefore, a remote attacker controlled DNS server can poison the router's DNS cache via malicious responses with additional and untrue records.
Impact
Base Score 3.x
7.50
Severity 3.x
HIGH
Base Score 2.0
5.00
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* | 6.44.5 (including) | |
| cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* | 6.45.6 (including) |
To consult the complete list of CPE names with products and versions, see this page



