CVE-2017-6444: High severity Mikrotik RouterOS vulnerability
The MikroTik Router hAP Lite 6.25 has no protection mechanism for unsolicited TCP ACK packets in the case of a fast network connection, which allows remote attackers to cause a denial of service (CPU consumption) by sending many ACK packets. After the attacker stops the exploit, the CPU usage is 100% and the router requires a reboot for normal operation.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTik Router hAP Liteto a version that resolves this vulnerability.Fixed in 6.25 - Compensating control
Mitigate the denial-of-service condition by blocking or rate-limiting unsolicited TCP ACK packets at the network edge (e.g., firewall/ACL/WAF) until the router is patched.
Event History
Frequently Asked Questions
What is the severity of CVE-2017-6444?
CVE-2017-6444 is classified as a medium severity vulnerability due to its potential to cause a denial of service.
How do I fix CVE-2017-6444?
To mitigate CVE-2017-6444, upgrade your MikroTik RouterOS to a version newer than 6.25.
What type of attack does CVE-2017-6444 enable?
CVE-2017-6444 enables remote denial of service attacks through the exploitation of unsolicited TCP ACK packets.
Which devices are affected by CVE-2017-6444?
CVE-2017-6444 specifically affects MikroTik Router hAP Lite running RouterOS version 6.25.
What is the impact of CVE-2017-6444 on the device?
The impact of CVE-2017-6444 includes increased CPU consumption leading to potential denial of service for legitimate users.