CVE CVE-2022-45315
Severity CRITICAL · CVSS 3.1 9.8
Weakness CWE-125
Affected versions < 7.6 2022-10-31
First non-vulnerable version 7.6 2022-10-31 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2022-12-05
Discrepant sources cvss_v31: cve@mitre.org → 6.4, nvd@nist.gov → 9.8, 134c704f-9b21-4f2e-91b3-4a467353bcc0 → 9.8; affected_versions: CVE.org → ['< 7.6 2022-10-31'], NVD CPE → ['< 7.6']

What is the CVE-2022-45315 vulnerability?

This is an Out-of-bounds Read error present in the SNMP process of RouterOS. This weakness allows an authenticated attacker to execute arbitrary code by sending a specific packet.

Which RouterOS versions are vulnerable?

RouterOS versions prior to 7.6, released on October 31, 2022, are affected. Sources cite a discrepancy in the exact notation: CVE.org indicates “< 7.6 2022-10-31” while NVD CPE indicates “< 7.6”. The specific corrective version was not communicated in the provided dataset, but upgrading to 7.6 or later resolves the issue.

Is my router at risk?

A router is exposed if it runs a RouterOS version prior to 7.6 and has the SNMP service active and reachable from untrusted networks. If SNMP is not used for monitoring, the risk is drastically reduced by disabling the service.

Is the CVE-2022-45315 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of active exploitation in the cited databases.

How to protect the router from CVE-2022-45315?

Update RouterOS to a stable version later than 7.6. Alternatively, if SNMP is not required for network operations, completely disable the SNMP service to eliminate the attack surface.

Which RouterOS commands are needed to mitigate CVE-2022-45315?

Temporary mitigation: snmp service

The defect concerns SNMP. If there is no monitoring system using it, it should be turned off.

/snmp set enabled=no

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2022-45315?

The CVSS v3.1 score assigned by NVD is 9.8 (Critical). There is a discrepancy between sources: MITRE reports 6.4, while NVD and another source report 9.8.

Does CVE-2022-45315 require authentication?

Yes, the description indicates that the attack requires the attacker to be authenticated on the system.

Is disabling SNMP enough to protect against CVE-2022-45315?

Yes, since the vulnerability resides in the SNMP process, disabling the service eliminates the specific attack vector of this CVE.

What is the weakness (CWE) associated with CVE-2022-45315?

The weakness is classified as CWE-125: Out-of-bounds Read.

Official sources