Vulnerabilities > CVE-2021-41987 - Out-of-bounds Write vulnerability in Mikrotik Routeros 6.46.8/6.47.10/6.47.9

047910
CVSS 8.1 - HIGH
Attack vector
NETWORK
Attack complexity
HIGH
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
HIGH
Availability impact
HIGH
network
high complexity
mikrotik
CWE-787

Summary

In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.

Vulnerable Configurations

Part Description Count
OS
Mikrotik
3

Common Weakness Enumeration (CWE)