CVE-2018-1157: Medium severity mikrotik routeros vulnerability
Published Aug 23, 2018
·Updated
Mikrotik RouterOS before 6.42.7 and 6.40.9 is vulnerable to a memory exhaustion vulnerability. An authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system via a crafted HTTP POST request.
Affected Software
2 affected components
MikroTik RouterOS<6.40.9
MikroTik RouterOS<6.42.7
Event History
Aug 23, 2018
CVE Published
via MITRE·07:00 PM
Data Sourced
via MITRE·07:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-1157?
The severity of CVE-2018-1157 is considered medium due to the potential for denial of service affecting affected MikroTik RouterOS versions.
2
How do I fix CVE-2018-1157?
To fix CVE-2018-1157, upgrade your MikroTik RouterOS to version 6.40.10 or later, or version 6.42.8 or later.
3
Who is affected by CVE-2018-1157?
CVE-2018-1157 affects MikroTik RouterOS versions prior to 6.42.7 and 6.40.9.
4
What is the impact of exploiting CVE-2018-1157?
Exploiting CVE-2018-1157 can lead to the HTTP server crashing and, in some cases, a reboot of the MikroTik device.
5
Is authentication required to exploit CVE-2018-1157?
Yes, an authenticated remote attacker is required to exploit CVE-2018-1157.