CVE-2023-41570
MEDIUMCVSS 5.3/10EPSS 0.47%
Last modified
CVE-2023-41570 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.. EPSS estimates a 0.47% chance of exploitation in the next 30 days.
Description
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | >= 7.1, < 7.12 |
References
- https://www.enricobassetti.it/2023/11/cve-2023-41570-access-control-vulnerability-in-mikrotik-rest-api/Exploit, Third Party Advisory
- https://www.enricobassetti.it/2023/11/cve-2023-41570-access-control-vulnerability-in-mikrotik-rest-api/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2023-41570?
MikroTik RouterOS v7.1 to 7.11 was discovered to contain incorrect access control mechanisms in place for the Rest API.
How severe is CVE-2023-41570?
CVE-2023-41570 has a CVSS score of 5.3/10 (MEDIUM severity). The EPSS model estimates a 0.47% probability of exploitation in the next 30 days.
How do I fix CVE-2023-41570?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2023
- CVE-2023-41561Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RT…9.8
- CVE-2023-41562Tenda AC7 V1.0 V15.03.06.44, Tenda AC9 V3.0 V15.03.06.42_mul…9.8
- CVE-2023-41563Tenda AC9 V3.0 V15.03.06.42_multi and Tenda AC5 US_AC5V1.0RT…9.8
- CVE-2023-41564An arbitrary file upload vulnerability in the Upload Asset f…6.1
- CVE-2023-41566OA EKP v16 was discovered to contain an arbitrary download v…8.1
- CVE-2023-4157CWE-74 Improper Neutralization of Special Elements in Output…4.8
- CVE-2023-41575Multiple stored cross-site scripting (XSS) vulnerabilities i…5.4
- CVE-2023-41578Jeecg boot up to v3.5.3 was discovered to contain an arbitra…7.5
- CVE-2023-4158Cross-site Scripting (XSS) - Stored in GitHub repository ome…5.4
- CVE-2023-41580Phpipam before v1.5.2 was discovered to contain a LDAP injec…7.5
- CVE-2023-41588A cross-site scripting (XSS) vulnerability in Time to SLA pl…6.1
- CVE-2023-4159Unrestricted Upload of File with Dangerous Type in GitHub re…8.8
Are you affected by CVE-2023-41570?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
