Community discussions

MikroTik App
 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Mikrotik 6.48 TCP timestamps Vulnerability

Mon Jan 04, 2021 8:05 am

I have Mikrotik 6.48 VM Machine it works fine.
When I When I scan my network for Vulnerabilities I get this

TCP timestamps OID: 1.3.6.1.4.1.25623.1.0.80091

I google it but I can not find a solution to remove this Vulnerability.

Can Any one help Please ??
 
User avatar
jprietove
Trainer
Trainer
Posts: 212
Joined: Fri Jun 03, 2016 3:00 pm
Location: Cádiz, Spain
Contact:

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Mon Jan 04, 2021 10:33 am

If you are not using SNMP, disable it.
If you use it, Just change the SNMP community and don't use "public". And use v2 or v3 with authentication.
 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Tue Jan 05, 2021 12:44 pm

Thanks for your response but SNMP is already disabled on my router

[attachment=0]Mik0.jpg[/attachment]
You do not have the required permissions to view the files attached to this post.
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 897
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Tue Jan 05, 2021 12:57 pm

User Cha0s has answered this question earlier on SO:

https://serverfault.com/questions/88496 ... tik-router

AFAIK you cannot disable this on MikroTik.
 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Wed Jan 06, 2021 7:03 am

The Problem is that Vulnerability Scanners consider TCP timestamps as Vulnerability
So Mikrotik should take this in consideration .
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1347
Joined: Mon Sep 23, 2019 1:04 pm

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Wed Jan 06, 2021 8:16 am

What services is your MikroTik Router providing to the outside (wild wild internet) that you consider this a vulnerability?
 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Wed Jan 06, 2021 10:23 am

For me I do not have problems but for my manager he recommended to remove and vulnerability
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1347
Joined: Mon Sep 23, 2019 1:04 pm

Re: Mikrotik 6.48 TCP timestamps Vulnerability  [SOLVED]

Wed Jan 06, 2021 10:56 am

MikroTik can respond with timestamps only for the services running on it (winbox, www etc) services which should be accessible only from trusted zones (Management VLAN, allowed IP list etc.).
So fix your security issues first and there won't be any "vulnerability".
For the DSTNATed ports you have take care of the "issue" on the destination machines.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Wed Jan 06, 2021 6:25 pm

 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Sun Jan 17, 2021 9:30 am

Now I get another vulnerability



SSL/TLS: Report 'Anonymous' Cipher Suites OID: 1.3.6.1.4.1.25623.1.0.108147


Any Help
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1347
Joined: Mon Sep 23, 2019 1:04 pm

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Sun Jan 17, 2021 12:40 pm

yes, fix it like you've fixed the one above.
 
amsteen
Member Candidate
Member Candidate
Topic Author
Posts: 180
Joined: Sat Apr 04, 2009 11:09 am

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Sun Jan 17, 2021 12:42 pm

I did not fix the first one
 
nescafe2002
Forum Veteran
Forum Veteran
Posts: 897
Joined: Tue Aug 11, 2015 12:46 pm
Location: Netherlands

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Sun Jan 17, 2021 2:14 pm

This has been discussed before: https://www.reddit.com/r/mikrotik/comme ... _mikrotik/

Disabling/firewalling www-ssl and api-ssl should fix the issue.

If you're concerned about security, you should learn to properly and securely configure (e.g. firewall) the device.
 
User avatar
Znevna
Forum Guru
Forum Guru
Posts: 1347
Joined: Mon Sep 23, 2019 1:04 pm

Re: Mikrotik 6.48 TCP timestamps Vulnerability

Sun Jan 17, 2021 2:52 pm

Same advice I gave him above to fix his "tcp timestamps". If he would've done that, both of these "vulnerabilities" wouldn't be an "issue" -- secure your devices or pay someone to do it for you.
But the nut didn't stick to the wall.

Who is online

Users browsing this forum: Bing [Bot], m3das and 116 guests