← Back

CVE-2018-7445

nvd nist
Published: Mar 19, 2018Modified: Nov 7, 2025CISA KEV

JSON object

Loading...
9.8
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitability: 3.9 / Impact: 5.9
Source: NVD

Description

A buffer overflow was found in the MikroTik RouterOS SMB service when processing NetBIOS session request messages. Remote attackers with access to the service can exploit this vulnerability and gain code execution on the system. The overflow occurs before authentication takes place, so it is possible for an unauthenticated remote attacker to exploit it. All architectures and all devices running RouterOS before versions 6.41.3/6.42rc27 are vulnerable.

Affected (13)

Products: Mikrotik: Routeros
1 product
Routeros
Configuration A
13 vulnerable
Vulnerable SoftwareAffected Versions
Mikrotik
Before 6.41.3
Version 6.42 rc11
Version 6.42 rc12
Version 6.42 rc14
Version 6.42 rc15
Version 6.42 rc18
Version 6.42 rc20
Version 6.42 rc23
Version 6.42 rc24
Version 6.42 rc2
Version 6.42 rc5
Version 6.42 rc6
Version 6.42 rc9

References (9)

Source: cve@mitre.org
ExploitMailing ListThird Party AdvisoryVDB Entry
Source: cve@mitre.org
Third Party AdvisoryVDB Entry
Source: cve@mitre.org
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.