CVE-2017-17537: Input Validation
Published Dec 13, 2017
·Updated
MikroTik RouterBOARD v6.39.2 and v6.40.5 allows an unauthenticated remote attacker to cause a denial of service by connecting to TCP port 53 and sending data that begins with many '\0' characters, possibly related to DNS.
Affected Software
3 affected components
Mikrotik RouterBOARD=6.39.2
Mikrotik RouterBOARD=6.40.5
Mikrotik RouterBOARD
Event History
Dec 13, 2017
CVE Published
via MITRE·04:00 PM
Data Sourced
via MITRE·04:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2017-17537?
CVE-2017-17537 is classified as a denial of service vulnerability.
2
How do I fix CVE-2017-17537?
To mitigate CVE-2017-17537, upgrade your MikroTik RouterBOARD to versions later than 6.40.5.
3
Which MikroTik RouterBOARD versions are affected by CVE-2017-17537?
CVE-2017-17537 affects MikroTik RouterBOARD versions 6.39.2 and 6.40.5.
4
Can CVE-2017-17537 be exploited remotely?
Yes, CVE-2017-17537 can be exploited remotely by connecting to TCP port 53.
5
What type of attack does CVE-2017-17537 enable?
CVE-2017-17537 enables an unauthenticated remote attacker to cause a denial of service.