Horizon Alert
Summary of the vulnerability and why it matters
A critical vulnerability has been identified in RouterOS, affecting how it verifies SSH authentication keys. This could allow an unauthorized individual to gain access as a legitimate user without possessing the private key. The main concern is to confirm if this specific technology is in use within our environment and assess any potential exposure.
- Key verification flaw allows unauthorized SSH access.
- Critical issue impacts network router authentication.
- Confirm relevance and potential exposure.
Attack Path
How an attacker could exploit the issue
An attacker can exploit this vulnerability by initiating an SSH connection to a vulnerable router. By crafting a malicious authentication request, they can bypass standard security checks that omit parts of the RSA public key verification. This allows the attacker to impersonate an authorized user and gain access to the router's command line.
- Entry condition: Network access to the router.
- Trigger point: SSH authentication request with a forged signature.
- Resulting risk: Unauthorized command execution as a user.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow an attacker to impersonate an authorized user over SSH by exploiting a weakness in how public keys are matched. When supported by the advisory, an attacker could gain access to the router's command channel by providing a crafted public key with an exponent of one, bypassing the need for the actual private key.
- Router command channel and user access at risk.
- Attacker provides weak public key for authentication.
- Unauthorized command execution could occur.
Operational Fix
Recommended remediation, mitigation, and detection steps
This critical vulnerability in RouterOS impacts the RSA public key comparison during SSH authentication. Infrastructure and network security teams are primarily responsible for managing and securing these routers. The immediate first step is to identify all deployed instances of RouterOS, determine their internet reachability and business criticality, and locate the accountable system owner. Subsequently, a risk-based remediation plan should be developed, considering vendor coordination for applying the necessary updates.
- Own by Infrastructure and Network Security teams.
- Verify SSH exposure and device criticality.
- Plan and coordinate vendor updates.