CVE-2023-30799: MikroTik RouterOS Administrator Privilege Escalation
MikroTik RouterOS stable before 6.49.7 and long-term through 6.48.6 are vulnerable to a privilege escalation issue. A remote and authenticated attacker can escalate privileges from admin to super-admin on the Winbox or HTTP interface. The attacker can abuse this vulnerability to execute arbitrary code on the system.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-30799?
The severity of CVE-2023-30799 is critical with a CVSS score of 7.2.
How can an attacker exploit CVE-2023-30799?
An attacker can exploit CVE-2023-30799 by escalating privileges from admin to super-admin on the Winbox or HTTP interface.
What is the affected software of CVE-2023-30799?
The affected software of CVE-2023-30799 is MikroTik RouterOS stable versions before 6.49.7 and long-term versions through 6.48.6.
How can I fix CVE-2023-30799?
To fix CVE-2023-30799, it is recommended to update MikroTik RouterOS to version 6.49.7 or later.
Are there any references available for CVE-2023-30799?
Yes, you can refer to the following links for more information about CVE-2023-30799: - [MikroTik Foisted Advisory](https://vulncheck.com/advisories/mikrotik-foisted) - [FOISted GitHub Repository](https://github.com/MarginResearch/FOISted)