First published: Tue Aug 18 2009(Updated: )
MikroTik RouterOS 3.x through 3.13 and 2.x through 2.9.51 allows remote attackers to modify Network Management System (NMS) settings via a crafted SNMP set request.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik devices | >=2.0<=2.9.51 | |
MikroTik devices | >=3.0<=3.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-6976 is considered high due to its potential impact on network management settings.
To fix CVE-2008-6976, upgrade MikroTik RouterOS to version 3.14 or later in the 3.x line or to a version higher than 2.9.51 in the 2.x line.
CVE-2008-6976 affects MikroTik RouterOS versions 2.x up to 2.9.51 and 3.x up to 3.13.
CVE-2008-6976 can be exploited by remote attackers sending crafted SNMP set requests to modify NMS settings on affected devices.
There is no official workaround for CVE-2008-6976; the only mitigation is to update to a non-vulnerable version.