MikroTik RouterOS Winbox Unauthenticated Arbitrary File Read/Write Vulnerability

critical Nessus Plugin ID 117335

Synopsis

The remote networking device is affected by an unauthenticated arbitrary file read/write vulnerability.

Description

The remote networking device is running a version of MikroTik RouterOS vulnerable to an unauthenticated arbitrary file read and write vulnerability. An unauthenticated attacker could leverage this vulnerability to read or write protected files on the affected host.
Nessus was able to exploit this vulnerability to retrieve the device credential store.

Solution

Upgrade to MikroTik RouterOS 6.40.8 / 6.42.1 / 6.43rc4 or later.

See Also

https://github.com/BasuCert/WinboxPoC

https://n0p.me/winbox-bug-dissection/

https://blog.mikrotik.com/security/winbox-vulnerability.html

http://www.nessus.org/u?25ba70ca

Plugin Details

Severity: Critical

ID: 117335

File Name: mikrotik_cve_2018-14847.nasl

Version: 1.7

Type: remote

Family: Misc.

Published: 9/6/2018

Updated: 4/11/2022

Risk Information

CVSS Score Source: CVE-2018-14847

CVSS Score Rationale: Vulnerability allows reads and writes to the file system

VPR

Risk Factor: High

Score: 8.8

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C

Temporal Vector: E:POC/RL:OF/RC:C

CVSS v3

Risk Factor: Critical

Base Score: 10

Temporal Score: 9

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Temporal Vector: E:P/RL:O/RC:C

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 4/23/2018

Vulnerability Publication Date: 4/23/2018

CISA Known Exploited Dates: 6/1/2022

Reference Information

CVE: CVE-2018-14847