Heap-based Buffer Overflow in Mikrotik RouterOS SCEP Server
CVE-2021-41987
8.1HIGH
What is CVE-2021-41987?
A vulnerability exists in the SCEP Server of Mikrotik RouterOS which can be exploited through a heap-based buffer overflow. This flaw allows an attacker who knows the scep_server_name value to execute arbitrary code remotely. The affected versions include RouterOS 6.46.8, 6.47.9, and 6.47.10, making it essential for users to patch their systems promptly to mitigate potential risks.
References
EPSS Score
59% chance of being exploited in the next 30 days.
CVSS V3.1
Score:
8.1
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved