Record summary

CVE-2023-30800 has a selected CVSS score of 7.5 (high); EIP currently links 3 repository PoCs.

Description

The web server used by MikroTik RouterOS version 6 is affected by a heap memory corruption issue. A remote and unauthenticated attacker can corrupt the server's heap memory by sending a crafted HTTP request. As a result, the web interface crashes and is immediately restarted. The issue was fixed in RouterOS 6.49.10 stable. RouterOS version 7 is not affected.

Description source: CVE List

Exploitation context

Available material

Repository PoCs
3

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Sep 26, 2024 · Source: CVE List

Affected products and versions

1
ProductSourceVersion rangeStatus

Default status: affected

CVE List6.49.10unaffected
6.49.9affected
6.48.8affected

Proofs of concept

3

Repository PoCs

GitHubgriffinsectio/CVE-2023-30800_PoCRepository PoCby griffinsectioStars: 0Not analyzed2 files

741 B

GitHub

PoC details
GitHubgriffinsectio/CVE-2023-30800_PoC_goRepository PoCby griffinsectioStars: 0Not analyzed2 files

1.2 KiB

GitHub

PoC details
GitHubdiemaxxing/cve-2023-30800-multithread-doserRepository PoCby KhogenTheRabbitStars: 1Not analyzed3 files

37.0 KiB

GitHub

PoC details

References

2