Lucene search

K
cveTenableCVE-2019-3976
HistoryOct 29, 2019 - 7:15 p.m.

CVE-2019-3976

2019-10-2919:15:20
CWE-23
CWE-22
tenable
web.nvd.nist.gov
77
cve-2019-3976
routeros
vulnerability
directory creation
upgrade package
malicious package
authenticated user

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

47.8%

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below are vulnerable to an arbitrary directory creation vulnerability via the upgrade package’s name field. If an authenticated user installs a malicious package then a directory could be created and the developer shell could be enabled.

Affected configurations

Nvd
Node
mikrotikrouterosRange6.44.5ltr
OR
mikrotikrouterosRange6.45.6-
VendorProductVersionCPE
mikrotikrouteros*cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*
mikrotikrouteros*cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*

CNA Affected

[
  {
    "product": "MikroTik RouterOS",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below."
      }
    ]
  }
]

CVSS2

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:S/C:P/I:P/A:P

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

8.5

Confidence

High

EPSS

0.001

Percentile

47.8%

Related for CVE-2019-3976