CVE-2020-20212: Null Pointer Dereference
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20212?
CVE-2020-20212 is a memory corruption vulnerability in the Mikrotik RouterOs 6.44.5 (long-term tree) /nova/bin/console process.
How does CVE-2020-20212 affect MikroTik RouterOS?
CVE-2020-20212 in MikroTik RouterOS 6.44.5 (long-term tree) can be exploited by an authenticated remote attacker to cause a Denial of Service (NULL pointer dereference).
What is the severity of CVE-2020-20212?
The severity of CVE-2020-20212 is medium with a severity value of 6.5.
How can I fix CVE-2020-20212?
To fix CVE-2020-20212, it is recommended to update MikroTik RouterOS to a version that is not affected.
Where can I find more information about CVE-2020-20212?
More information about CVE-2020-20212 can be found at the following references: [1] http://seclists.org/fulldisclosure/2021/May/0 [2] https://mikrotik.com/