Community discussions

MikroTik App
 
za7
just joined
Topic Author
Posts: 19
Joined: Tue Mar 14, 2017 8:59 pm

Loop Dos CVE-2024-2169 Mikrotik

Thu Mar 21, 2024 6:30 pm

Loop DoS: New Denial-of-Service Attack targets Application-Layer Protocols
https://www.bleepingcomputer.com/news/s ... e-systems/
https://cispa.de/en/loop-dos
https://kb.cert.org/vuls/id/417980

Notified: 2024-01-17 Updated: 2024-03-19
Statement Date: January 17, 2024
CVE-2009-3563 Unknown
CVE-2024-1309 Unknown
CVE-2024-2169 Affected
Vendor Statement
Our TFTP service is affected, we have resolved the issue in 7.14beta6 version. Stable versions after 7.13.2 will include a patch for this issue.
 
User avatar
Larsa
Forum Guru
Forum Guru
Posts: 1068
Joined: Sat Aug 29, 2015 7:40 pm
Location: The North Pole, Santa's Workshop

Re: Loop Dos CVE-2024-2169 Mikrotik

Thu Mar 21, 2024 8:11 pm

Just a friendly reminder: Never ever expose TFTP or similar services directly to the internet. Doing so poses serious security risks, otherwise you don't have to worry about CVE-2024-2169.
 
R1CH
Forum Guru
Forum Guru
Posts: 1101
Joined: Sun Oct 01, 2006 11:44 pm

Re: Loop Dos CVE-2024-2169 Mikrotik

Fri Mar 22, 2024 5:44 pm

Calling this "new" in 2024... everything old is eventually rediscovered and called new I guess :D. This has been known about since the dawn of the internet. You should not be exposing such services to untrusted networks.
 
mada3k
Long time Member
Long time Member
Posts: 698
Joined: Mon Jul 13, 2015 10:53 am
Location: Sweden

Re: Loop Dos CVE-2024-2169 Mikrotik

Fri Mar 22, 2024 7:18 pm

Almost all UDP services can be exploited. Never leave them open to the wild.

Who is online

Users browsing this forum: Laxity, N2B and 22 guests