CVE-2018-1156: Buffer Overflow
Published Aug 23, 2018
·Updated
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to stack buffer overflow through the license upgrade interface. This vulnerability could theoretically allow a remote authenticated attacker execute arbitrary code on the system.
Affected Software
2 affected components
MikroTik RouterOS<6.40.9
MikroTik RouterOS<6.42.7
Event History
Aug 23, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1156?
CVE-2018-1156 has a moderate severity rating due to its potential to allow remote code execution.
2
How do I fix CVE-2018-1156?
To fix CVE-2018-1156, upgrade Mikrotik RouterOS to version 6.42.7 or 6.40.9 or later.
3
Who is affected by CVE-2018-1156?
CVE-2018-1156 affects all versions of Mikrotik RouterOS prior to 6.42.7 and 6.40.9.
4
Can CVE-2018-1156 be exploited remotely?
Yes, CVE-2018-1156 can be exploited remotely by an authenticated attacker.
5
What type of vulnerability is CVE-2018-1156?
CVE-2018-1156 is a stack buffer overflow vulnerability that can allow arbitrary code execution.