CVE CVE-2017-17538
Severity not yet disclosed
Weakness not yet disclosed
Affected versions not yet disclosed
Fixed version not yet disclosed
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2017-12-13

What is the CVE-2017-17538 vulnerability?

CVE-2017-17538 is a vulnerability that allows a remote attacker to cause a denial of service on MikroTik devices. The attack occurs by sending a massive sequence of ICMP packets (flood). The original description does not specify further technical details about the internal mechanism of the flaw.

Which RouterOS versions are vulnerable?

The version specified as vulnerable is 6.40.5. The affected versions and the exact fixed version have not been disclosed in the available sources. It is recommended to verify the complete list of affected versions directly with the vendor or in official vulnerability databases.

Is my router at risk?

A router is at risk if it is running RouterOS version 6.40.5 and is reachable from untrusted networks. Since the attack occurs via ICMP packets, any interface exposed to external traffic can be targeted. If the device is isolated in an internal network protected by firewalls that block incoming ICMP traffic, the risk is reduced, but updating remains the definitive solution.

Is the CVE-2017-17538 vulnerability actively exploited?

As of the date of the article, there is no evidence that this vulnerability is being actively exploited. It is not present in the CISA KEV catalog, and there are no reports from ENISA regarding active use in real-world attacks.

How to protect the router from CVE-2017-17538?

The primary solution is to update RouterOS to a version later than 6.40.5 that resolves the vulnerability. While waiting for the update, you can mitigate the risk by configuring network filters to limit or block incoming ICMP traffic from interfaces exposed to untrusted networks. It is important to ensure that perimeter firewalls are configured to protect internal devices from ICMP-based DoS attacks.

Which RouterOS commands are needed to mitigate CVE-2017-17538?

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

Does CVE-2017-17538 require authentication to be exploited?

No, the description indicates that the attack can be conducted by a remote attacker without the need for authentication, by sending ICMP packets.

What is the CVSS score for CVE-2017-17538?

The CVSS score has not been disclosed in the available sources. It is not possible to provide a numerical value or a specific severity classification.

Is disabling the ICMP service enough to protect against CVE-2017-17538?

Completely disabling ICMP traffic can mitigate the specific attack, but it is not always advisable because ICMP is also used for legitimate network functions such as diagnostics. The recommended solution is to update the firmware.

Is CVE-2017-17538 listed in the CISA KEV catalog?

No, CVE-2017-17538 is not listed in the CISA KEV catalog, which means it is not known to be actively exploited in attacks.

Official sources