MikroTik RouterOS SSL/TLS Renegotiation DoS Vulnerability
CVE-2022-36324 Published on August 10, 2022

Affected devices do not properly handle the renegotiation of SSL/TLS parameters. This could allow an unauthenticated remote attacker to bypass the TCP brute force prevention and lead to a denial of service condition for the duration of the attack.

NVD

Weakness Type

Allocation of Resources Without Limits or Throttling

The software allocates a reusable resource or group of resources on behalf of an actor without imposing any restrictions on the size or number of resources that can be allocated, in violation of the intended security policy for that actor.


Products Associated with CVE-2022-36324

Want to know whenever a new CVE is published for MikroTik Routeros? stack.watch will email you.

 

Affected Versions

Siemens RUGGEDCOM RM1224 LTE(4G) EU: Siemens RUGGEDCOM RM1224 LTE(4G) NAM: Siemens SCALANCE M804PB: Siemens SCALANCE M812-1 ADSL-Router (Annex A): Siemens SCALANCE M812-1 ADSL-Router (Annex B): Siemens SCALANCE M816-1 ADSL-Router (Annex A): Siemens SCALANCE M816-1 ADSL-Router (Annex B): Siemens SCALANCE M826-2 SHDSL-Router: Siemens SCALANCE M874-2: Siemens SCALANCE M874-3: Siemens SCALANCE M876-3 (EVDO): Siemens SCALANCE M876-3 (ROK): Siemens SCALANCE M876-4 (EU): Siemens SCALANCE M876-4 (NAM): Siemens SCALANCE MUM853-1 (EU): Siemens SCALANCE MUM856-1 (EU): Siemens SCALANCE MUM856-1 (RoW): Siemens SCALANCE S615: Siemens SCALANCE SC622-2C: Siemens SCALANCE SC626-2C: Siemens SCALANCE SC632-2C: Siemens SCALANCE SC636-2C: Siemens SCALANCE SC642-2C: Siemens SCALANCE SC646-2C: Siemens SCALANCE W1748-1 M12: Siemens SCALANCE W1748-1 M12: Siemens SCALANCE W1788-1 M12: Siemens SCALANCE W1788-2 EEC M12: Siemens SCALANCE W1788-2 M12: Siemens SCALANCE W1788-2IA M12: Siemens SCALANCE W721-1 RJ45: Siemens SCALANCE W721-1 RJ45: Siemens SCALANCE W722-1 RJ45: Siemens SCALANCE W722-1 RJ45: Siemens SCALANCE W722-1 RJ45: Siemens SCALANCE W734-1 RJ45: Siemens SCALANCE W734-1 RJ45: Siemens SCALANCE W734-1 RJ45: Siemens SCALANCE W734-1 RJ45 (USA): Siemens SCALANCE W738-1 M12: Siemens SCALANCE W738-1 M12: Siemens SCALANCE W748-1 M12: Siemens SCALANCE W748-1 M12: Siemens SCALANCE W748-1 RJ45: Siemens SCALANCE W748-1 RJ45: Siemens SCALANCE W761-1 RJ45: Siemens SCALANCE W761-1 RJ45: Siemens SCALANCE W774-1 M12 EEC: Siemens SCALANCE W774-1 M12 EEC: Siemens SCALANCE W774-1 RJ45: Siemens SCALANCE W774-1 RJ45: Siemens SCALANCE W774-1 RJ45: Siemens SCALANCE W774-1 RJ45: Siemens SCALANCE W774-1 RJ45 (USA): Siemens SCALANCE W778-1 M12: Siemens SCALANCE W778-1 M12: Siemens SCALANCE W778-1 M12 EEC: Siemens SCALANCE W778-1 M12 EEC (USA): Siemens SCALANCE W786-1 RJ45: Siemens SCALANCE W786-1 RJ45: Siemens SCALANCE W786-2 RJ45: Siemens SCALANCE W786-2 RJ45: Siemens SCALANCE W786-2 RJ45: Siemens SCALANCE W786-2 SFP: Siemens SCALANCE W786-2 SFP: Siemens SCALANCE W786-2IA RJ45: Siemens SCALANCE W786-2IA RJ45: Siemens SCALANCE W788-1 M12: Siemens SCALANCE W788-1 M12: Siemens SCALANCE W788-1 RJ45: Siemens SCALANCE W788-1 RJ45: Siemens SCALANCE W788-2 M12: Siemens SCALANCE W788-2 M12: Siemens SCALANCE W788-2 M12 EEC: Siemens SCALANCE W788-2 M12 EEC: Siemens SCALANCE W788-2 M12 EEC: Siemens SCALANCE W788-2 RJ45: Siemens SCALANCE W788-2 RJ45: Siemens SCALANCE W788-2 RJ45: Siemens SCALANCE WAM763-1: Siemens SCALANCE WAM766-1 (EU): Siemens SCALANCE WAM766-1 (US): Siemens SCALANCE WAM766-1 EEC (EU): Siemens SCALANCE WAM766-1 EEC (US): Siemens SCALANCE WUM763-1: Siemens SCALANCE WUM763-1: Siemens SCALANCE WUM766-1 (EU): Siemens SCALANCE WUM766-1 (US): Siemens SCALANCE XB205-3 (SC, PN): Siemens SCALANCE XB205-3 (ST, E/IP): Siemens SCALANCE XB205-3 (ST, E/IP): Siemens SCALANCE XB205-3 (ST, PN): Siemens SCALANCE XB205-3LD (SC, E/IP): Siemens SCALANCE XB205-3LD (SC, PN): Siemens SCALANCE XB208 (E/IP): Siemens SCALANCE XB208 (PN): Siemens SCALANCE XB213-3 (SC, E/IP): Siemens SCALANCE XB213-3 (SC, PN): Siemens SCALANCE XB213-3 (ST, E/IP): Siemens SCALANCE XB213-3 (ST, PN): Siemens SCALANCE XB213-3LD (SC, E/IP): Siemens SCALANCE XB213-3LD (SC, PN): Siemens SCALANCE XB216 (E/IP): Siemens SCALANCE XB216 (PN): Siemens SCALANCE XC206-2 (SC): Siemens SCALANCE XC206-2 (ST/BFOC): Siemens SCALANCE XC206-2G PoE: Siemens SCALANCE XC206-2G PoE (54 V DC): Siemens SCALANCE XC206-2G PoE EEC (54 V DC): Siemens SCALANCE XC206-2SFP: Siemens SCALANCE XC206-2SFP EEC: Siemens SCALANCE XC206-2SFP G: Siemens SCALANCE XC206-2SFP G (EIP DEF.): Siemens SCALANCE XC206-2SFP G EEC: Siemens SCALANCE XC208: Siemens SCALANCE XC208EEC: Siemens SCALANCE XC208G: Siemens SCALANCE XC208G (EIP def.): Siemens SCALANCE XC208G EEC: Siemens SCALANCE XC208G PoE: Siemens SCALANCE XC208G PoE (54 V DC): Siemens SCALANCE XC216: Siemens SCALANCE XC216-3G PoE: Siemens SCALANCE XC216-3G PoE (54 V DC): Siemens SCALANCE XC216-4C: Siemens SCALANCE XC216-4C G: Siemens SCALANCE XC216-4C G (EIP Def.): Siemens SCALANCE XC216-4C G EEC: Siemens SCALANCE XC216EEC: Siemens SCALANCE XC224: Siemens SCALANCE XC224-4C G: Siemens SCALANCE XC224-4C G (EIP Def.): Siemens SCALANCE XC224-4C G EEC: Siemens SCALANCE XF204: Siemens SCALANCE XF204 DNA: Siemens SCALANCE XF204-2BA: Siemens SCALANCE XF204-2BA DNA: Siemens SCALANCE XM408-4C: Siemens SCALANCE XM408-4C (L3 int.): Siemens SCALANCE XM408-8C: Siemens SCALANCE XM408-8C (L3 int.): Siemens SCALANCE XM416-4C: Siemens SCALANCE XM416-4C (L3 int.): Siemens SCALANCE XP208: Siemens SCALANCE XP208 (Ethernet/IP): Siemens SCALANCE XP208EEC: Siemens SCALANCE XP208PoE EEC: Siemens SCALANCE XP216: Siemens SCALANCE XP216 (Ethernet/IP): Siemens SCALANCE XP216EEC: Siemens SCALANCE XP216POE EEC: Siemens SCALANCE XR324WG (24 x FE, AC 230V): Siemens SCALANCE XR324WG (24 X FE, DC 24V): Siemens SCALANCE XR326-2C PoE WG: Siemens SCALANCE XR326-2C PoE WG (without UL): Siemens SCALANCE XR328-4C WG (24XFE, 4XGE, 24V): Siemens SCALANCE XR328-4C WG (24xFE, 4xGE,DC24V): Siemens SCALANCE XR328-4C WG (24xFE,4xGE,AC230V): Siemens SCALANCE XR328-4C WG (24xFE,4xGE,AC230V): Siemens SCALANCE XR328-4C WG (28xGE, AC 230V): Siemens SCALANCE XR328-4C WG (28xGE, DC 24V): Siemens SCALANCE XR524-8C, 1x230V: Siemens SCALANCE XR524-8C, 1x230V (L3 int.): Siemens SCALANCE XR524-8C, 24V: Siemens SCALANCE XR524-8C, 24V (L3 int.): Siemens SCALANCE XR524-8C, 2x230V: Siemens SCALANCE XR524-8C, 2x230V (L3 int.): Siemens SCALANCE XR526-8C, 1x230V: Siemens SCALANCE XR526-8C, 1x230V (L3 int.): Siemens SCALANCE XR526-8C, 24V: Siemens SCALANCE XR526-8C, 24V (L3 int.): Siemens SCALANCE XR526-8C, 2x230V: Siemens SCALANCE XR526-8C, 2x230V (L3 int.): Siemens SCALANCE XR528-6M: Siemens SCALANCE XR528-6M (2HR2, L3 int.): Siemens SCALANCE XR528-6M (2HR2): Siemens SCALANCE XR528-6M (L3 int.): Siemens SCALANCE XR552-12M: Siemens SCALANCE XR552-12M (2HR2, L3 int.): Siemens SCALANCE XR552-12M (2HR2): Siemens SCALANCE XR552-12M (2HR2): Siemens SIPLUS NET SCALANCE XC206-2: Siemens SIPLUS NET SCALANCE XC206-2SFP: Siemens SIPLUS NET SCALANCE XC208: Siemens SIPLUS NET SCALANCE XC216-4C:

Exploit Probability

EPSS
1.07%
Percentile
77.49%

EPSS (Exploit Prediction Scoring System) scores estimate the probability that a vulnerability will be exploited in the wild within the next 30 days. The percentile shows you how this score compares to all other vulnerabilities.