Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)
Summary
MikroTik has released a patch for a critical vulnerability that allows SSH authentication bypass. This vulnerability is already being actively exploited, with attackers creating new accounts on affected devices to ensure persistent access even after patching.
IFF Assessment
The active exploitation of a critical vulnerability allowing unauthorized access and persistent control on network devices is detrimental to defenders.
Severity
This vulnerability allows an attacker to bypass SSH authentication, leading to unauthorized access and potential system compromise. The high CVSS score reflects the critical nature of bypassing authentication and the potential for widespread impact on network devices.
Defender Context
This critical vulnerability in MikroTik devices demands immediate attention. Defenders should prioritize patching affected devices and actively hunt for signs of compromise, such as newly created user accounts, as the vulnerability is actively exploited.