CVE CVE-2019-3979
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-345
Affected versions RouterOS 6.45.6 Stable and below. RouterOS 6.44.5 Long-term and below.
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2019-10-29

What is the CVE-2019-3979 vulnerability?

The vulnerability consists of insufficient verification of data authenticity (CWE-345) during DNS response handling. The router adds all A records present in the response to its DNS cache, even if they are not related to the queried domain. A remote attacker controlling a DNS server can therefore send malicious responses containing additional and false records to poison the device’s cache.

Which RouterOS versions are vulnerable?

The affected versions are RouterOS 6.45.6 Stable and all previous versions, as well as RouterOS 6.44.5 Long-term and all previous versions. The exact fixed version has not yet been announced in the available data.

Is my router at risk?

The router is exposed if the DNS service is active and reachable from untrusted networks. If the device does not act as a DNS server for the internal network, remote requests must be disabled. If it provides DNS resolution to the LAN, incoming traffic from the WAN must be blocked to prevent a malicious external DNS server from sending poisoned responses.

Is the CVE-2019-3979 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog, and there are no reports from ENISA regarding active exploitation.

How to protect the router from CVE-2019-3979?

The primary measure is updating the firmware to a version later than the affected ones, if available. Alternatively or additionally, you can mitigate the risk by configuring the firewall to block incoming DNS requests from the untrusted network (WAN), especially if the router should not provide DNS services to external hosts.

Which RouterOS commands are needed to mitigate CVE-2019-3979?

Temporary mitigation: dns service

The defect concerns the router’s DNS resolver. If it does not act as a DNS server for the internal network, remote requests must be disabled; if it does, they must be blocked from the WAN.

/ip dns print
# se il router non fa da DNS ai client
/ip dns set allow-remote-requests=no
# se lo fa: blocca le richieste DNS che arrivano da internet
/ip firewall filter add chain=input in-interface-list=WAN protocol=udp dst-port=53 \
    action=drop place-before=0 comment="no DNS da WAN"

Update RouterOS

The only definitive fix is an update. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score of CVE-2019-3979?

CVE-2019-3979 has a CVSS v3.1 score of 7.5, classified as HIGH severity. The vector indicates a network attack with low complexity, no privileges or user interaction required, and high impact on integrity.

Does CVE-2019-3979 require authentication to be exploited?

No, CVE-2019-3979 does not require authentication. The attack occurs by sending malicious DNS responses to a router that queries a DNS server controlled by the attacker, without the need for credentials.

Is disabling the DNS service enough to protect against CVE-2019-3979?

Disabling remote DNS requests or blocking inbound DNS traffic from the WAN is an effective mitigation if the router does not need to provide DNS resolution to external hosts. If the router acts as a DNS server for the LAN, you still need to block requests coming from untrusted networks.

Is CVE-2019-3979 listed in the CISA KEV catalog?

No, CVE-2019-3979 is not listed in the CISA KEV catalog. It is therefore not tracked by CISA as a vulnerability actively exploited in known attacks.

Official sources