← Back

CVE-2019-3943

nvd nist
Published: Apr 10, 2019Modified: Nov 21, 2024

JSON object

Loading...
8.1
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Exploitability: 2.8 / Impact: 5.2
Source: NVD

Description

MikroTik RouterOS versions Stable 6.43.12 and below, Long-term 6.42.12 and below, and Testing 6.44beta75 and below are vulnerable to an authenticated, remote directory traversal via the HTTP or Winbox interfaces. An authenticated, remote attack can use this vulnerability to read and write files outside of the sandbox directory (/rw/disk).

Affected (75)

Products: Mikrotik: Routeros
1 product
Routeros
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Mikrotik
Up to 6.43.12
Up to 6.42.12
Configuration B
73 vulnerable
Vulnerable SoftwareAffected Versions
Mikrotik
Version 6.41 rc31
Version 6.41 rc32
Version 6.41 rc34
Version 6.41 rc37
Version 6.41 rc38
Version 6.41 rc44
Version 6.41 rc47
Version 6.41 rc50
Version 6.41 rc52
Version 6.41 rc56
Version 6.41 rc61
Version 6.41 rc66
Version 6.42 rc11
Version 6.42 rc12
Version 6.42 rc14
Version 6.42 rc15
Version 6.42 rc18
Version 6.42 rc20
Version 6.42 rc23
Version 6.42 rc24
Version 6.42 rc27
Version 6.42 rc28
Version 6.42 rc2
Version 6.42 rc30
Version 6.42 rc35
Version 6.42 rc37
Version 6.42 rc39
Version 6.42 rc41
Version 6.42 rc43
Version 6.42 rc46
Version 6.42 rc48
Version 6.42 rc49
Version 6.42 rc52
Version 6.42 rc56
Version 6.42 rc5
Version 6.42 rc6
Version 6.42 rc9
Version 6.43 rc11
Version 6.43 rc12
Version 6.43 rc14
Version 6.43 rc17
Version 6.43 rc19
Version 6.43 rc21
Version 6.43 rc23
Version 6.43 rc27
Version 6.43 rc29
Version 6.43 rc32
Version 6.43 rc34
Version 6.43 rc3
Version 6.43 rc40
Version 6.43 rc42
Version 6.43 rc44
Version 6.43 rc45
Version 6.43 rc4
Version 6.43 rc51
Version 6.43 rc56
Version 6.43 rc5
Version 6.43 rc64
Version 6.43 rc66
Version 6.43 rc6
Version 6.43 rc7
Version 6.44 beta14
Version 6.44 beta17
Version 6.44 beta20
Version 6.44 beta28
Version 6.44 beta39
Version 6.44 beta40
Version 6.44 beta50
Version 6.44 beta54
Version 6.44 beta61
Version 6.44 beta6
Version 6.44 beta75
Version 6.44 beta9

References (2)

Source: vulnreport@tenable.com
ExploitThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party Advisory

Timeline

No history available yet.