Vulnerability Description
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | <= 6.48.7 |
Related Weaknesses (CWE)
References
- https://github.com/MarginResearch/FOIStedThird Party Advisory
- https://vulncheck.com/advisories/mikrotik-foistedThird Party Advisory
- https://github.com/MarginResearch/FOIStedThird Party Advisory
- https://vulncheck.com/advisories/mikrotik-foistedThird Party Advisory
FAQ
What is CVE-2023-30799?
CVE-2023-30799 is a vulnerability with a CVSS score of 9.1 (CRITICAL). MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admi...
How severe is CVE-2023-30799?
CVE-2023-30799 has been rated CRITICAL with a CVSS base score of 9.1/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-30799?
Check the references section above for vendor advisories and patch information. Affected products include: Mikrotik Routeros.