CVE CVE-2023-24094
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-787
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2023-03-27

What is the CVE-2023-24094 vulnerability?

CVE-2023-24094 is an issue in the bridge2 component of MikroTik RouterOS v6.40.5 that allows an attacker to cause a Denial of Service (DoS) by sending specially crafted packets. The underlying weakness is classified as Out-of-bounds Write (CWE-787).

Which RouterOS versions are vulnerable?

The affected versions and fixed versions have not yet been announced. Available sources specifically indicate version v6.40.5 as affected, but do not provide a complete list of vulnerable versions or a fixed stable version.

Is my router at risk?

A router is exposed if it runs MikroTik RouterOS v6.40.5 and the bridge2 component is active and reachable from untrusted networks. Since the network-exploitable vulnerability (AV:N) does not require authentication (PR:N), any host capable of sending packets to the router can potentially exploit the weakness to cause a service interruption.

Is the CVE-2023-24094 vulnerability actively exploited?

As of the date of the article, there is no evidence that CVE-2023-24094 is being actively exploited. The vulnerability is not present in the CISA KEV catalog, and ENISA does not report it as exploited.

How to protect the router from CVE-2023-24094?

Since fixed versions and vendor-specific mitigations have not yet been announced, the primary action is to monitor official MikroTik announcements for the release of a fixed stable version. Pending the update, it is recommended to limit the reachability of the bridge2 component from untrusted networks, for example through firewall configurations that block unnecessary traffic towards bridging services, if compatible with your network architecture.

Which RouterOS commands are needed to mitigate CVE-2023-24094?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2023-24094?

The CVSS v3.1 score for CVE-2023-24094 is 7.5, with HIGH severity. The vector indicates that the attack occurs over the network, has low complexity, requires no privileges or user interaction, and the main impact is on integrity (actually on availability, given A:H).

Does CVE-2023-24094 require authentication to be exploited?

No, CVE-2023-24094 does not require authentication. The CVSS vector indicates PR:N (Privileges Required: None), which means an unauthenticated attacker can exploit the vulnerability.

What is the type of weakness associated with CVE-2023-24094?

The weakness associated with CVE-2023-24094 is Out-of-bounds Write (CWE-787). This type of error can lead to memory corruption and, in this specific case, to a Denial of Service.

Is CVE-2023-24094 present in the CISA KEV catalog?

No, CVE-2023-24094 is not present in the CISA KEV (Known Exploited Vulnerabilities) catalog. The vulnerability is therefore not known to be actively exploited in attacks.

Official sources