nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2023-30800 CVE-2023-30800
HIGH
MikroTik RouterOS Web Interface Heap Corruption
Record summary
CVE-2023-30800 has a selected CVSS score of 7.5 (high); EIP currently links 3 repository PoCs.
Description
The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.
Description source: CVE List
Exploitation context
Available material
- Repository PoCs
- 3
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
RouterOSBrowse MikroTik / RouterOSDefault status: affected | CVE List | 6.49.10 | unaffected |
| 6.49.9 | affected | ||
| 6.48.8 | affected |
Proofs of concept
3Repository PoCs
GitHubgriffinsectio/CVE-2023-30800_PoCRepository PoCby griffinsectioStars: 0Not analyzed2 files
GitHubgriffinsectio/CVE-2023-30800_PoC_goRepository PoCby griffinsectioStars: 0Not analyzed2 files
GitHubdiemaxxing/cve-2023-30800-multithread-doserRepository PoCby KhogenTheRabbitStars: 1Not analyzed3 files
References
2vulncheck.com
https://vulncheck.com/advisories/mikrotik-jsproxy-dos