MikroTik RouterOS Winbox Unauthenticated Arbitrary File Read/Write Vulnerability

Critical Nessus Plugin ID 117335

Synopsis

The remote networking device is affected by an unauthenticated arbitrary file read/write vulnerability.

Description

The remote networking device is running a version of MikroTik RouterOS vulnerable to an unauthenticated arbitrary file read and write vulnerability. An unauthenticated attacker could leverage this vulnerability to read or write protected files on the affected host.
Nessus was able to exploit this vulnerability to retrieve the device credential store.

Solution

Upgrade to MikroTik RouterOS 6.40.8 / 6.42.1 / 6.43rc4 or later.

See Also

https://github.com/BasuCert/WinboxPoC

https://n0p.me/winbox-bug-dissection/

https://blog.mikrotik.com/security/winbox-vulnerability.html

http://www.nessus.org/u?25ba70ca

Plugin Details

Severity: Critical

ID: 117335

File Name: mikrotik_cve_2018-14847.nasl

Version: 1.3

Type: remote

Family: Misc.

Published: 2018/09/06

Modified: 2018/10/10

Dependencies: 59731

Risk Information

Risk Factor: Critical

CVSS Score Source: manual

CVSS Score Rationale: Vulnerability allows reads and writes to the file system

CVSS v2.0

Base Score: 10

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS v3.0

Base Score: 10

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/o:mikrotik:routeros

Patch Publication Date: 2018/04/23

Vulnerability Publication Date: 2018/04/23

Reference Information

CVE: CVE-2018-14847