CVE-2017-8338: High severity mikrotik routeros vulnerability
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2017-8338?
The severity of CVE-2017-8338 is classified as critical due to its potential to cause a denial of service.
How do I fix CVE-2017-8338?
To fix CVE-2017-8338, upgrade your MikroTik RouterOS to a version later than 6.38.5 that addresses this vulnerability.
Who is affected by CVE-2017-8338?
CVE-2017-8338 specifically affects devices running MikroTik RouterOS version 6.38.5.
What is the impact of CVE-2017-8338?
CVE-2017-8338 can allow an unauthenticated attacker to exhaust the CPU resources of the router, causing a denial of service.
Can CVE-2017-8338 be exploited remotely?
Yes, CVE-2017-8338 can be exploited remotely through a flood of UDP packets directed at port 500.