#VU17851 Input validation error in MikroTik RouterOS - CVE-2019-3924
Published: February 25, 2019 / Updated: June 17, 2021
MikroTik RouterOS
MikroTik
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to insufficient validation of user-supplied input within the Winbox service. A remote attacker can send a specially crafted request to the affected service and trigger denial of service conditions.
Successful exploitation of the vulnerability requires that the Winbox service is exposed to the attacker.