CVE-2019-13074: High severity mikrotik routeros vulnerability
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13074?
CVE-2019-13074 is considered to be of high severity due to its potential to allow remote attackers to exhaust device memory.
How do I fix CVE-2019-13074?
To mitigate CVE-2019-13074, upgrade the MikroTik router to version 6.44.4 or higher that contains the necessary security patches.
What systems are affected by CVE-2019-13074?
CVE-2019-13074 affects MikroTik routers running RouterOS version 6.44.3 or earlier.
What exploitation method is used in CVE-2019-13074?
CVE-2019-13074 can be exploited by remote attackers through the FTP daemon to consume excessive memory resources.
Are there any known workarounds for CVE-2019-13074?
As a workaround for CVE-2019-13074, disabling the FTP service on vulnerable MikroTik devices can help prevent exploitation.