CVE-2023-30799
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2023
Last modified:
28/07/2023
Description
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Impact
Base Score 3.x
7.20
Severity 3.x
HIGH
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* | 6.48.7 (including) | |
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* | 6.34 (including) | 6.49.7 (excluding) |
To consult the complete list of CPE names with products and versions, see this page