На форуме операторов UKNOF 46 9 апреля обещают раскрыть детали уязвимости, которая может вызывать отказ оборудования на RouterOS, которое доступно по #IPv6.
https://indico.uknof.org.uk/event/46/contributions/667/
Из описания:
During some research which found CVE-2018-19298 (MikroTik IPv6 Neighbor Discovery Protocol exhaustion), I uncovered a larger problem with MikroTik RouterOS’s handling of IPv6 packets. This led to CVE-2018-19299, an unpublished and as yet unfixed (despite almost one year elapsing since vendor acknowledgement) vulnerability in RouterOS which allows for remote, unauthenticated denial of service. Unpublished… until UKNOF 43!
Ответ от normis (MikroTik Support) https://forum.mikrotik.com/viewtopic.php?f=2&t=147048
28 Mar 2019, 16:50
We are aware of this issue and are working on it.
-----
Деталей пока нет, но рекомендую внимательно следить за новостями на форуме MikroTik и обновлениями RouterOS.
Post #129
1.68K