CVE CVE-2023-41570
Severity MEDIUM · CVSS 3.1 5.3
Weakness CWE-284
Affected versions < 7.12
First non-vulnerable version 7.12 (per branch)
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2023-11-14

What is the CVE-2023-41570 vulnerability?

The CVE-2023-41570 vulnerability consists of improper access control mechanisms implemented in the RouterOS REST API. This flaw, classified as “Improper Access Control” (CWE-284), allows an attacker with limited privileges to gain unauthorized access to confidential information through the API interface.

Which RouterOS versions are vulnerable?

The RouterOS versions affected by CVE-2023-41570 are those between 7.1 and 7.11, inclusive. The fixed version is 7.12. No other specific versions or beta/RC variants have been communicated as a definitive solution; upgrading to the stable release 7.12 is the recommended mitigation.

Is my router at risk?

A router is exposed to CVE-2023-41570 if it runs a RouterOS version between 7.1 and 7.11 and has the REST API enabled. The risk materializes if the API is reachable from untrusted networks or if it is not restricted to the specific hosts that legitimately use it. If the REST API is not used by any management software or scripts, the router is not exposed to this specific attack vector.

Is the CVE-2023-41570 vulnerability actively exploited?

As of the date of this article, CVE-2023-41570 is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of known active exploitation.

How to protect the router from CVE-2023-41570?

The primary solution is to upgrade RouterOS to version 7.12 or higher, which fixes the access control flaw. Pending the upgrade, you can mitigate the risk by disabling the REST API if it is not necessary, or by configuring firewall rules to restrict API access exclusively to the IP addresses of authorized hosts.

Which RouterOS commands are needed to mitigate CVE-2023-41570?

Temporary mitigation: api service

The flaw concerns the RouterOS API, used by scripts and management software. If no program uses it, disable it; otherwise, restrict it to the hosts that call it.

/ip service print
# se l'API non serve
/ip service set api disabled=yes
/ip service set api-ssl disabled=yes
# se serve: solo dagli host che la usano (sostituisci con i tuoi)
/ip service set api-ssl address=192.168.88.10/32

Upgrade RouterOS

The only definitive fix is the upgrade. Save the configuration first; the installation will reboot the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2023-41570?

The CVSS v3.1 score assigned to CVE-2023-41570 is 5.3, with MEDIUM severity. The vector indicates a network attack with high complexity, requiring low privileges and no user interaction, with high impact on confidentiality but no impact on integrity or availability.

Is authentication required to exploit CVE-2023-41570?

Yes, using the REST API requires authentication. The vulnerability CVE-2023-41570 exploits a flaw in post-authentication access control, allowing a user with low privileges to access data they should not have rights to.

Is disabling the REST API enough to protect against CVE-2023-41570?

Yes, disabling the REST API completely eliminates the attack vector for CVE-2023-41570, as the vulnerability resides exclusively in that component. However, if the API is required for network management, disabling it is not a practical option, and you must resort to updating or restricting access.

Which RouterOS version fixes CVE-2023-41570?

The RouterOS version that fixes CVE-2023-41570 is 7.12. All previous versions, from 7.1 to 7.11 inclusive, remain vulnerable and must be updated to eliminate the risk.

Official sources