CVE-2017-8338
PoC ×4—CVSS 3.0
7.5 high
EPSS
4%p90
Published
()
Modified
Description
A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
- Vendors
- mikrotik
- Products
- routeros
- Weakness
- CWE-400
- Vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
In the news0 stories
No ingested article mentions this CVE yet.