Lucene search

K
cvelistTenableCVELIST:CVE-2019-3977
HistoryOct 28, 2019 - 9:34 p.m.

CVE-2019-3977

2019-10-2821:34:37
CWE-494
tenable
www.cve.org
1

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.0%

RouterOS 6.45.6 Stable, RouterOS 6.44.5 Long-term, and below insufficiently validate where upgrade packages are download from when using the autoupgrade feature. Therefore, a remote attacker can trick the router into “upgrading” to an older version of RouterOS and possibly reseting all the system’s usernames and passwords.

CNA Affected

[
  {
    "product": "MikroTik RouterOS",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below."
      }
    ]
  }
]

7.7 High

AI Score

Confidence

High

0.002 Low

EPSS

Percentile

55.0%

Related for CVELIST:CVE-2019-3977