CVE-2019-3924: High severity Mikrotik RouterOS vulnerability
MikroTik RouterOS before 6.43.12 (stable) and 6.42.12 (long-term) is vulnerable to an intermediary vulnerability. The software will execute user defined network requests to both WAN and LAN clients. A remote unauthenticated attacker can use this vulnerability to bypass the router's firewall or for general network scanning activities.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-3924?
CVE-2019-3924 has a high severity rating due to its potential for remote unauthenticated exploitation.
How do I fix CVE-2019-3924?
To fix CVE-2019-3924, update MikroTik RouterOS to versions 6.43.12 or later or 6.42.12 for long-term support.
Who is affected by CVE-2019-3924?
CVE-2019-3924 affects MikroTik RouterOS versions prior to 6.43.12 and 6.42.12.
What kind of attacks can exploit CVE-2019-3924?
CVE-2019-3924 can be exploited for bypassing firewall rules and executing unauthorized commands by remote attackers.
Is CVE-2019-3924 a known vulnerability?
Yes, CVE-2019-3924 is a known vulnerability that has been publicly disclosed and documented.