The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
History

Thu, 26 Sep 2024 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2023-09-07T15:43:54.429Z

Updated: 2024-09-26T19:04:47.706Z

Reserved: 2023-04-18T10:31:45.962Z

Link: CVE-2023-30800

cve-icon Vulnrichment

Updated: 2024-08-02T14:37:15.351Z

cve-icon NVD

Status : Modified

Published: 2023-09-07T16:15:07.670

Modified: 2024-11-21T08:00:55.653

Link: CVE-2023-30800

cve-icon Redhat

No data.