CVE-2020-20211: Medium severity mikrotik routeros vulnerability
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20211?
CVE-2020-20211 is a vulnerability in MikroTik RouterOS 6.44.5 (long-term tree) that allows an authenticated remote attacker to cause a Denial of Service (DoS) via a crafted packet.
How severe is CVE-2020-20211?
CVE-2020-20211 has a severity score of 6.5 (medium).
What is the affected version of MikroTik RouterOS?
The affected version of MikroTik RouterOS is 6.44.5 (long-term tree).
How can an attacker exploit CVE-2020-20211?
An authenticated remote attacker can exploit CVE-2020-20211 by sending a crafted packet to the /nova/bin/console process.
Are there any known mitigations for CVE-2020-20211?
At the moment, there are no known mitigations for CVE-2020-20211. It is recommended to update to a patched version of MikroTik RouterOS when available.