8.1

CVE-2021-41987

Exploit
In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MikrotikRouteros Version6.46.8
MikrotikRouteros Version6.47.9
MikrotikRouteros Version6.47.10
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 16.23% 0.965
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 8.1 2.2 5.9
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-787 Out-of-bounds Write

The product writes data past the end, or before the beginning, of the intended buffer.

https://mikrotik.com/download/archive
Vendor Advisory
Release Notes
https://teamt5.org/en/posts/vulnerability-mikrotik-cve-2021-41987/
Third Party Advisory
Exploit