CVE-2020-11881 PATCH

To be precise .. github checked a while ago … no 7.2 or 7.3 version … only old test beta ones:
11881.PNG
I’m not Devil’s advocate of MT but if you start rocking a boat please give references to facts.
There were some 6.48.x versions after 6.47 and there is 7.3 now so maybe “is still” is not justified.

@millap Did you even read that screenshot?
Or do you need some other tool to do that for you? :slight_smile:

@millap your “scan/detection tool” is terrible…

It is going show an issue with every 7. release because it says that 7.x is vulnerable. From that screenshot, until RouterOS v8 comes out, it will keep showing the warnings.

You could also avoid it completely by turning off the SMB server in RouterOS, which I haven’t found a good use-case yet for turning it on anyways.

I bet it’s not even enabled.

Still interesting if this fixed in 7.x tree, I just looked at all changelogs and cant see any fix

Tell me clearly where it says 7.1 (stable) and later are vulnerable.

Because it's not wrote in any changelog from 7.0 beta till 7.10.0. Can support clear say, yes it's vulnerable or no it's not, that's not hard.

Okay, just to be clear.
I installed latest stable 7.10 and test it with https://github.com/botlabsDev/CVE-2020-11881

The result was

[smb]: online
[dos]: ok
[smb]: online

And smbclient result after this

Anonymous login successful

        Sharename       Type      Comment
        ---------       ----      -------
SMB1 disabled -- no workgroup available

So I think its fixed, just not reported

The fix is in all branches and issue does not affect any version on our download page, as you can verify using above mentioned tests.