CVE-2008-6976: Input Validation
Published Aug 18, 2009
·Updated
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.
Affected Software
2 affected components
Mikrotik RouterOS>=2.0<=2.9.51
Mikrotik RouterOS>=3.0<=3.13
Event History
Aug 18, 2009
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2008-6976?
The severity of CVE-2008-6976 is considered high due to its potential impact on network management settings.
2
How do I fix CVE-2008-6976?
To fix CVE-2008-6976, upgrade MikroTik RouterOS to version 3.14 or later in the 3.x line or to a version higher than 2.9.51 in the 2.x line.
3
What types of devices are affected by CVE-2008-6976?
CVE-2008-6976 affects MikroTik RouterOS versions 2.x up to 2.9.51 and 3.x up to 3.13.
4
What kind of attack can exploit CVE-2008-6976?
CVE-2008-6976 can be exploited by remote attackers sending crafted SNMP set requests to modify NMS settings on affected devices.
5
Is there a known workaround for CVE-2008-6976?
There is no official workaround for CVE-2008-6976; the only mitigation is to update to a non-vulnerable version.