Heap-based Buffer Overflow in Mikrotik RouterOS SCEP Server
CVE-2021-41987

8.1HIGH

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
16 March 2022

What is CVE-2021-41987?

A vulnerability exists in the SCEP Server of Mikrotik RouterOS which can be exploited through a heap-based buffer overflow. This flaw allows an attacker who knows the scep_server_name value to execute arbitrary code remotely. The affected versions include RouterOS 6.46.8, 6.47.9, and 6.47.10, making it essential for users to patch their systems promptly to mitigate potential risks.

References

EPSS Score

59% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.