Blog | G5 Cyber Security

DNS cache poisoning vulnerability

Tenable has identified a vulnerability in RouterOS DNS implementation. RouterOS 6.45.6 and below is vulnerable to unauthenticated remote DNS cache poisoning via Winbox. The router is impacted even when DNS is not enabled. The issue is fixed in router versions:RouterOS6.46beta59 [testing] and 6.7 [stable]6.44.6 [long-term] With the following changelog entry: “Security – fixed improper handling of DNS responses (CVE-2019-3978)”]

Source: https://blog.mikrotik.com/security/dns-cache-poisoning-vulnerability.html

Exit mobile version