CVE-2019-15055
Last modified
CVE-2019-15055 is a vulnerability of currently unknown severity. MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.. EPSS estimates a 2.23% chance of exploitation in the next 30 days.
Description
MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | <= 6.44.5 |
| Mikrotik | Routeros | >= 6.45, <= 6.45.3 |
References
- https://fortiguard.com/zeroday/FG-VD-19-108Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055Exploit, Third Party Advisory
- https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90Press/Media Coverage, Third Party Advisory
- https://mikrotik.com/download/changelogs/testing-release-treeRelease Notes, Vendor Advisory
- https://fortiguard.com/zeroday/FG-VD-19-108Third Party Advisory
- https://github.com/tenable/routeros/tree/master/poc/cve_2019_15055Exploit, Third Party Advisory
- https://medium.com/tenable-techblog/rooting-routeros-with-a-usb-drive-16d7b8665f90Press/Media Coverage, Third Party Advisory
- https://mikrotik.com/download/changelogs/testing-release-treeRelease Notes, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2019-15055?
How severe is CVE-2019-15055?
How do I fix CVE-2019-15055?
Are you affected by CVE-2019-15055?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
