9 April 2019
Scanning IPv6 Address Space… and the remote vulnerabilities it uncovers

9 Apr 2019, 17:40
Marek Isalski (Faelix Limited)


During some research which found CVE-2018-19298 (MikroTik IPv6 Neighbor Discovery Protocol exhaustion), I uncovered a larger problem with MikroTik RouterOS’s handling of IPv6 packets. This led to CVE-2018-19299, an unpublished and as yet unfixed (despite almost one year elapsing since vendor acknowledgement) vulnerability in RouterOS which allows for remote, unauthenticated denial of service. Unpublished… until UKNOF 43!


Previously given at NetMcr (today). Two attendees suggested this as material for UKNOF43.

Primary author

Marek Isalski (Faelix Limited)

