PoC Index

CVE-2019-15055

MEDIUM 6.5EPSS 2.2%

MikroTik RouterOS through 6.44.5 and 6.45.x through 6.45.3 improperly handles the disk name, which allows authenticated users to delete arbitrary files. Attackers can exploit this vulnerability to reset credential storage, which allows them access to the management interface as an administrator without authentication.

CVSS v3.0
6.5 MEDIUMCVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
CVSS v2.0
5.5 MEDIUMAV:N/AC:L/Au:S/C:N/I:P/A:P
EPSS
2.23% chance of exploitation in the next 30 days, 82th percentile
Published
2019-08-26
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related