Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

Summary

MikroTik has released a patch for a critical vulnerability that allows SSH authentication bypass. This vulnerability is already being actively exploited, with attackers creating new accounts on affected devices to ensure persistent access even after patching.

IFF Assessment

FOE

The active exploitation of a critical vulnerability allowing unauthorized access and persistent control on network devices is detrimental to defenders.

Severity

9.8 Critical (AI Estimated)

This vulnerability allows an attacker to bypass SSH authentication, leading to unauthorized access and potential system compromise. The high CVSS score reflects the critical nature of bypassing authentication and the potential for widespread impact on network devices.

Defender Context

This critical vulnerability in MikroTik devices demands immediate attention. Defenders should prioritize patching affected devices and actively hunt for signs of compromise, such as newly created user accounts, as the vulnerability is actively exploited.

Read Full Story →