CVE Vulnerabilities

CVE-2023-30799

Published: Jul 19, 2023 | Modified: Jul 28, 2023
CVSS 3.x
7.2
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.

Affected Software

Name Vendor Start Version End Version
Routeros Mikrotik * 6.48.7 (including)
Routeros Mikrotik 6.34 (including) 6.49.7 (excluding)

References