MikroTik RouterOS Cross Site Request Forgery Vulnerability
BID:73013
Info
MikroTik RouterOS Cross Site Request Forgery Vulnerability
| Bugtraq ID: | 73013 |
| Class: | Input Validation Error |
| CVE: |
CVE-2015-2350 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 08 2015 12:00AM |
| Updated: | Apr 13 2015 09:03PM |
| Credit: | Mohamed Abdelbaset Elnoby |
| Vulnerable: |
MikroTik RouterOS 2.9.51 MikroTik RouterOS 2.9.50 MikroTik RouterOS 2.9.49 MikroTik RouterOS 2.9.48 MikroTik RouterOS 2.9.47 MikroTik RouterOS 2.9.46 MikroTik RouterOS 2.9.45 MikroTik RouterOS 2.9.44 MikroTik RouterOS 2.9.43 MikroTik RouterOS 2.9.42 MikroTik RouterOS 2.9.41 MikroTik RouterOS 2.9.40 MikroTik RouterOS 4.0 MikroTik RouterOS 3.2 MikroTik RouterOS 3.13 MikroTik RouterOS 3.12 MikroTik RouterOS 3.11 MikroTik RouterOS 3.10 MikroTik RouterOS 3.09 MikroTik RouterOS 3.08 MikroTik RouterOS 3.07 MikroTik RouterOS 3.0 |
| Not Vulnerable: |
MikroTik RouterOS 5.0 |
Discussion
MikroTik RouterOS Cross Site Request Forgery Vulnerability
MikroTik RouterOS is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
MikroTik RouterOS is prone to a cross-site request-forgery vulnerability because it fails to properly validate HTTP requests.
Exploiting this issue may allow a remote attacker to perform certain unauthorized actions and gain access to the affected application. Other attacks are also possible.
Exploit / POC
MikroTik RouterOS Cross Site Request Forgery Vulnerability
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
An attacker can exploit this issue by enticing an unsuspecting user to follow a malicious URI.
Solution / Fix
MikroTik RouterOS Cross Site Request Forgery Vulnerability
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this.Please contact the vendor for more information.
Solution:
Reportedly the issue is fixed, however Symantec has not confirmed this.Please contact the vendor for more information.
References
MikroTik RouterOS Cross Site Request Forgery Vulnerability
References:
References:
- MikroTik RouterOS Admin Password Change CSRF (Mohamed A. Baset)
- MikroTik Homepage (MikroTik )