CVE-2019-15055
Summary
| CVE | CVE-2019-15055 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-26 21:15:00 UTC |
| Updated | 2020-10-06 12:15:00 UTC |
| Description | MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication. |
Risk And Classification
Problem Types: CWE-22
NVD Known Affected Configurations (CPE 2.3)
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Fortinet Discovers MikroTik RouterOS Authenticated Arbitrary File Deletion Vulnerability | FortiGuard | MISC | fortiguard.com | Third Party Advisory |
| Rooting RouterOS with a USB Drive - Tenable TechBlog - Medium | MISC | medium.com | Press/Media Coverage, Third Party Advisory |
| routeros/poc/cve_2019_15055 at master · tenable/routeros · GitHub | MISC | github.com | Exploit, Third Party Advisory |
| MikroTik Routers and Wireless - Software | CONFIRM | mikrotik.com | Release Notes, Vendor Advisory |
| v6.45.5 [stable] is released! - MikroTik | CONFIRM | forum.mikrotik.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.