CVE CVE-2023-30799
Severity HIGH · CVSS 3.1 7.2
Weakness CWE-269
Affected versions < 6.49.7, <= 6.48.6
First non-vulnerable version 6.49.7 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2023-07-19
Discrepant sources cvss_v31: disclosure@vulncheck.com → 9.1, nvd@nist.gov → 7.2; affected_versions: CVE.org → ['< 6.49.7', '<= 6.48.6'], NVD CPE → ['< 6.49.7']

What is the CVE-2023-30799 vulnerability?

CVE-2023-30799 is an improper privilege management flaw (CWE-269) that allows a remote, authenticated attacker to escalate their rights from admin to super-admin through the Winbox or HTTP interface. Once super-admin privileges are obtained, the attacker can execute arbitrary code on the system.

Which RouterOS versions are vulnerable?

The vulnerable versions are stable releases prior to 6.49.7 and long-term releases up to and including 6.48.6. The exact corrective version is not specified in the available data, but the update must bring the system to a release later than those indicated as affected.

Is my router at risk?

A router is exposed if it runs one of the vulnerable versions and if the Winbox or HTTP interface is reachable from untrusted networks. The risk materializes only if an attacker already holds valid credentials for an admin account, as the vulnerability requires authentication.

Is the CVE-2023-30799 vulnerability actively exploited?

As of the date of the article, CVE-2023-30799 is not listed in the CISA KEV catalog nor reported as exploited by ENISA.

How to protect the router from CVE-2023-30799?

The primary protection is to update RouterOS to a version later than the vulnerable releases. Pending the update, you must restrict access to the Winbox and HTTP interfaces to the trusted administration network only, preventing reachability from external or untrusted networks.

Which RouterOS commands are needed to mitigate CVE-2023-30799?

Temporary mitigation: winbox service

The flaw affects Winbox, both via IP and via MAC address. Both access methods must be restricted to the administration network.

/ip service print
# Winbox via IP solo dalla rete di gestione (sostituisci con la tua)
/ip service set winbox address=192.168.88.0/24
# Winbox via MAC: spegnilo, o limitalo a un'interface-list di gestione
/tool mac-server mac-winbox set allowed-interface-list=none

Update RouterOS

The only definitive fix is the update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2023-30799 require authentication?

Yes, CVE-2023-30799 requires the attacker to hold valid credentials for an admin account before they can exploit the flaw.

What is the CVSS score assigned to CVE-2023-30799?

The CVSS v3.1 score reported by NVD is 7.2 (HIGH), while the source disclosure@vulncheck.com indicates a value of 9.1. There is therefore a discrepancy between sources regarding the exact score.

Which long-term versions are affected by CVE-2023-30799?

The affected long-term versions are those up to and including 6.48.6, according to CVE.org data. The NVD CPE source instead indicates only versions prior to 6.49.7, without explicitly specifying the limit for long-term releases.

Does disabling Winbox eliminate the risk of CVE-2023-30799?

Disabling Winbox reduces the attack surface, but the vulnerability also affects the HTTP interface. For complete mitigation, it is necessary to protect or disable both involved interfaces.

Is CVE-2023-30799 present in the CISA KEV catalog?

No, CVE-2023-30799 is not included in the CISA KEV catalog as of the date of this article.

Official sources