Vulnerabilities > CVE-2021-41987 - Out-of-bounds Write vulnerability in Mikrotik Routeros 6.46.8/6.47.10/6.47.9

047910
CVSS 6.8 - MEDIUM
Attack vector
NETWORK
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
PARTIAL
Availability impact
PARTIAL

Summary

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.

Vulnerable Configurations

Part Description Count
OS
Mikrotik
3

Common Weakness Enumeration (CWE)