CVE-2019-13954: Medium severity mikrotik routeros vulnerability
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to memory exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server and in some circumstances reboot the system. Malicious code cannot be injected.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-13954?
CVE-2019-13954 has a medium severity rating due to the potential for system crashes and reboots.
How do I fix CVE-2019-13954?
To fix CVE-2019-13954, upgrade Mikrotik RouterOS to version 6.44.5 or later.
What types of devices are affected by CVE-2019-13954?
CVE-2019-13954 affects MikroTik devices running RouterOS versions prior to 6.44.5 and version 6.45.
Can CVE-2019-13954 allow remote code execution?
No, CVE-2019-13954 does not allow remote code execution; it only causes memory exhaustion leading to server crashes.
What causes the vulnerability in CVE-2019-13954?
CVE-2019-13954 is caused by an authenticated remote attacker sending a crafted HTTP request that exhausts the server's memory.