CVE-2019-13955: Medium severity mikrotik routeros vulnerability
Published Jul 26, 2019
·Updated
Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server via recursive parsing of JSON. Malicious code cannot be injected.
Affected Software
2 affected components
Mikrotik RouterOS<6.44.5
Mikrotik RouterOS=6.45
Event History
Jul 26, 2019
CVE Published
via MITRE·12:13 PM
Data Sourced
via MITRE·12:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2019-13955?
CVE-2019-13955 is a high severity vulnerability due to its potential to crash the HTTP server.
2
How do I fix CVE-2019-13955?
To mitigate CVE-2019-13955, upgrade MikroTik RouterOS to version 6.44.5 or above.
3
Who is affected by CVE-2019-13955?
CVE-2019-13955 affects MikroTik RouterOS versions before 6.44.5 and the 6.45 release.
4
What type of attack is associated with CVE-2019-13955?
CVE-2019-13955 allows authenticated remote attackers to perform a stack exhaustion attack.
5
Can malicious code be injected through CVE-2019-13955?
No, CVE-2019-13955 does not allow for malicious code injection, only service disruption.