CVE CVE-2017-6444
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-400
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2017-03-12

What is the CVE-2017-6444 vulnerability?

The original description states that the MikroTik Router hAP Lite 6.25 lacks protection mechanisms against unsolicited TCP ACK packets in the case of a fast network connection. This allows a remote attacker to cause a denial of service (CPU consumption) by sending many ACK packets. After the attack ceases, CPU usage remains at 100% and the router requires a reboot to become operational again.

Which RouterOS versions are vulnerable?

The affected versions and fixed versions have not yet been disclosed. The description specifies that the issue concerns firmware 6.25 on the hAP Lite device.

Is my router at risk?

A router is exposed if it runs firmware 6.25 on the hAP Lite model and is reachable from untrusted networks. The involved services have not been specified, but the nature of the vulnerability (TCP ACK packets) implies that the attack occurs at the network level, without the need for authentication.

Is the CVE-2017-6444 vulnerability actively exploited?

As of the date of the article, it is not reported as exploited. The vulnerability is not present in the CISA KEV catalog, and ENISA does not report it as exploited.

How to protect the router from CVE-2017-6444?

Since fixed versions have not been disclosed, updating the firmware may not resolve the issue. Mitigation consists of isolating the hAP Lite 6.25 device from any untrusted network, for example by removing its exposure to the Internet or placing it behind a firewall that blocks unsolicited TCP ACK traffic. Alternatively, it is advisable to replace the device with a newer, supported model.

Which RouterOS commands are needed to mitigate CVE-2017-6444?

Update RouterOS

The only definitive fix is an update. First, save the configuration; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2017-6444 require authentication to be exploited?

No, CVE-2017-6444 does not require authentication. The attack vector is remote (AV:N) and does not require privileges (PR:N), as indicated by the CVSS 3.1 score.

What is the CVSS score for CVE-2017-6444?

The CVSS 3.1 score for CVE-2017-6444 is 7.5, with HIGH severity. The vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H.

Is CVE-2017-6444 present in the CISA KEV catalog?

No, CVE-2017-6444 is not present in the CISA KEV catalog. The date of addition to the catalog has not been disclosed.

What are the weaknesses (CWE) associated with CVE-2017-6444?

The weakness associated with CVE-2017-6444 is CWE-400, named “Uncontrolled Resource Consumption”.

Official sources