CVE-2020-20216: Null Pointer Dereference
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/graphing process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability CVE-2020-20216?
CVE-2020-20216 is a memory corruption vulnerability in the /nova/bin/graphing process of Mikrotik RouterOS 6.44.6 (long-term tree).
How does this vulnerability affect Mikrotik RouterOS?
This vulnerability can cause a Denial of Service (NULL pointer dereference) on Mikrotik RouterOS 6.44.6 (long-term tree) when exploited by an authenticated remote attacker.
What is the severity of CVE-2020-20216?
The severity of CVE-2020-20216 is medium with a CVSS score of 6.5.
How can I mitigate this vulnerability?
To mitigate CVE-2020-20216, update Mikrotik RouterOS to a version that is not vulnerable or apply the patches provided by MikroTik.
Where can I find more information about this vulnerability?
For more information about CVE-2020-20216, you can visit the following references: http://seclists.org/fulldisclosure/2021/May/10 and https://mikrotik.com/