CVE-2017-7285: High severity Mikrotik RouterOS vulnerability
A vulnerability in the network stack of MikroTik Version 6.38.5 released 2017-03-09 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of TCP RST packets, preventing the affected router from accepting new TCP connections.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MikroTikto a version that resolves this vulnerability.Fixed in 6.38.5
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7285?
CVE-2017-7285 is considered a critical vulnerability due to its potential to disrupt network services by exhausting CPU resources.
How does CVE-2017-7285 affect MikroTik routers?
CVE-2017-7285 allows an unauthenticated remote attacker to flood the router with TCP RST packets, preventing it from accepting new TCP connections.
How do I fix CVE-2017-7285?
To mitigate CVE-2017-7285, it is recommended to upgrade the MikroTik RouterOS to a version beyond 6.38.5 that addresses this vulnerability.
Who is affected by CVE-2017-7285?
CVE-2017-7285 specifically affects MikroTik RouterOS version 6.38.5.
Is there a workaround for CVE-2017-7285?
There are no known workarounds for CVE-2017-7285 other than upgrading to a patched version of RouterOS.