Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

Test ID:1.3.6.1.4.1.25623.1.0.140895
Category:General
Title:MikroTik RouterOS < 6.41.3 RCE Vulnerability
Summary:MikroTik RouterOS is prone to a remote code execution (RCE); vulnerability in the SMB service.
Description:Summary:
MikroTik RouterOS is prone to a remote code execution (RCE)
vulnerability in the SMB service.

Vulnerability Insight:
The buffer overflow was found in the MikroTik RouterOS SMB
service when processing NetBIOS session request messages. Remote attackers with access to the
service can exploit this vulnerability and gain code execution on the system. The overflow occurs
before authentication takes place, so it is possible for an unauthenticated remote attacker to
exploit it.

Affected Software/OS:
MikroTik RouterOS prior to version 6.41.3.

Solution:
Update to version 6.41.3 or later.

CVSS Score:
10.0

CVSS Vector:
AV:N/AC:L/Au:N/C:C/I:C/A:C

Cross-Ref: Common Vulnerability Exposure (CVE) ID: CVE-2018-7445
BugTraq ID: 103427
http://www.securityfocus.com/bid/103427
https://www.exploit-db.com/exploits/44290/
http://seclists.org/fulldisclosure/2018/Mar/38
https://www.coresecurity.com/advisories/mikrotik-routeros-smb-buffer-overflow
CopyrightCopyright (C) 2018 Greenbone AG

This is only one of 145615 vulnerability tests in our test suite. Find out more about running a complete security audit.

To run a free test of this vulnerability against your system, register below.




© 1998-2025 E-Soft Inc. All rights reserved.