In the SCEP Server of RouterOS in certain Mikrotik products, an attacker can trigger a heap-based buffer overflow that leads to remote code execution. The attacker must know the scep_server_name value. This affects RouterOS 6.46.8, 6.47.9, and 6.47.10.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-04T03:22:25.697Z
Reserved: 2021-10-04T00:00:00
Link: CVE-2021-41987
No data.
Status : Modified
Published: 2022-03-16T15:15:14.547
Modified: 2024-11-21T06:27:01.380
Link: CVE-2021-41987
No data.
OpenCVE Enrichment
No data.
Weaknesses