CVE-2019-3978 is a critical vulnerability affecting MikroTik RouterOS versions 6.45.6 Stable, 6.44.5 Long-term, and below, allowing remote unauthenticated attackers to trigger DNS queries. This vulnerability has a CVSS score of 7.5 (High) due to its network-based attack vector, low complexity, and potential for DNS cache poisoning, leading to integrity impact. While not on the KEV catalog, exploit code is publicly available on ExploitDB, and it has garnered significant community discussion and media coverage, indicating active awareness and potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 6.44.5CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:* | ||
<= 6.45.6CPE matchmatch criteria | cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019MikroTik RouterOS Multiple Vulnerabilities
Oct 28, 2019