ID

VAR-201807-2272


TITLE

Mikrotik Winbox Arbitrary File Access Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2018-12706

DESCRIPTION

MikroTikRouterOS is a routing operating system based on Linux kernel development, compatible with x86PC routing software, which can be used to turn a standard PC into a professional router. Winbox is a software for remotely managing RouterOS based on Windows, providing an intuitive and convenient graphical interface. There are arbitrary file access vulnerabilities in MikrotikWinbox. An attacker can download arbitrary files, including the user database file of RouterOS, through a carefully constructed request package.

Trust: 0.6

sources: CNVD: CNVD-2018-12706

IOT TAXONOMY

category:['Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2018-12706

AFFECTED PRODUCTS

vendor:mikrotikmodel:winboxscope:gteversion:6.29,<=6.42

Trust: 0.6

sources: CNVD: CNVD-2018-12706

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2018-12706
value: HIGH

Trust: 0.6

CNVD: CNVD-2018-12706
severity: HIGH
baseScore: 7.5
vectorString: AV:N/AC:L/AU:N/C:P/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: PARTIAL
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 6.4
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2018-12706

PATCH

title:MikrotikWinbox patch for arbitrary file access vulnerabilitiesurl:https://www.cnvd.org.cn/patchinfo/show/133823

Trust: 0.6

sources: CNVD: CNVD-2018-12706

EXTERNAL IDS

db:CNVDid:CNVD-2018-12706

Trust: 0.6

sources: CNVD: CNVD-2018-12706

REFERENCES

url:https://github.com/basucert/winboxpoc

Trust: 0.6

url:https://n0p.me/winbox-bug-dissection/

Trust: 0.6

sources: CNVD: CNVD-2018-12706

SOURCES

db:CNVDid:CNVD-2018-12706

LAST UPDATE DATE

2022-05-04T09:39:04.468000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2018-12706date:2018-07-06T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2018-12706date:2018-07-06T00:00:00