CVE-2020-10364: High severity mikrotik routeros vulnerability
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-10364?
CVE-2020-10364 is characterized as a medium severity vulnerability that can lead to denial-of-service conditions on affected MikroTik routers.
How do I fix CVE-2020-10364?
To fix CVE-2020-10364, ensure your MikroTik RouterOS is updated to a version later than 6.44.3.
What is the impact of CVE-2020-10364?
CVE-2020-10364 allows remote attackers to generate excessive CPU load, potentially causing service disruptions and router reboots.
Which MikroTik devices are affected by CVE-2020-10364?
CVE-2020-10364 affects MikroTik RouterOS versions up to and including 6.44.3 across various MikroTik devices.
Are there any reported exploits for CVE-2020-10364?
Yes, there are public reports of exploits leveraging CVE-2020-10364 that demonstrate the denial-of-service capability.