Page 15 of 73 results (0.001 seconds)

CVSS: 7.8EPSS: 1%CPEs: 1EXPL: 2

A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections. Vulnerabilidad en la pila de la red de MikroTik Version 6.38.5 liberada 09-03-2017 podría permitir a un atacante remoto no autenticado agotar toda la CPU disponible a través de una inundación de paquetes TCP RST, evitando que el enrutador afectado acepte nuevas conexiones TCP. Mikrotik RouterBoard version 6.38.5 suffers from a denial of service vulnerability. • https://www.exploit-db.com/exploits/41752 http://www.securityfocus.com/bid/97266 https://cxsecurity.com/issue/WLB-2017030242 • CWE-400: Uncontrolled Resource Consumption •

CVSS: 7.8EPSS: 1%CPEs: 2EXPL: 4

The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation. El router MikroTik hAP Lite 6.25 no tiene mecanismo de protección para paquetes TCP ACK no solicitados en el caso de una conexión de red rápida. lo que permite a atacantes remotos provocar una denegación de servicio (consumo de CPU) enviando muchos paquetes ACK. Después de que el atacante detenga el exploit, el uso de CPU es 100% y el router requiere un reinicio para un funcionamiento normal • https://www.exploit-db.com/exploits/41601 http://www.exploitalert.com/view-details.html?id=26137 https://cxsecurity.com/issue/WLB-2017030029 https://packetstormsecurity.com/files/141449/Mikrotik-Hap-Lite-6.25-Denial-Of-Service.html • CWE-400: Uncontrolled Resource Consumption •

CVSS: 5.9EPSS: 0%CPEs: 2EXPL: 1

The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret. El Cliente L2TP en MikroTik RouterOS versiones 6.83.3 y 6.37.4 no habilita el cifrado IPsec después de un reinicio, lo que permite a atacantes man-in-the-middle ver los datos transmitidos sin cifrar y obtener acceso a las redes en el servidor L2TP monitorizando los paquetes para los datos transmitidos y obtener el secreto L2TP. • http://www.securityfocus.com/bid/96447 https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297 • CWE-311: Missing Encryption of Sensitive Data •