First published: Mon May 03 2021(Updated: )
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | =6.44.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2020-20218 is medium with a CVSS score of 6.5.
The affected software of CVE-2020-20218 is MikroTik RouterOS version 6.44.6 (long-term tree).
CVE-2020-20218 is a memory corruption vulnerability.
An authenticated remote attacker can cause a Denial of Service by exploiting the memory corruption vulnerability in the /nova/bin/traceroute process.
Yes, references for CVE-2020-20218 can be found at: [link1](https://seclists.org/fulldisclosure/2020/May/30), [link2](https://seclists.org/fulldisclosure/2021/May/1).