CVE-2020-20218: Medium severity mikrotik routeros vulnerability
Published May 3, 2021
·Updated
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/traceroute process. An authenticated remote attacker can cause a Denial of Service due via the loop counter variable.
Affected Software
1 affected component
Mikrotik RouterOS=6.44.6
Event History
May 3, 2021
CVE Published
via MITRE·03:13 PM
Data Sourced
via MITRE·03:13 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2020-20218?
The severity of CVE-2020-20218 is medium with a CVSS score of 6.5.
2
What is the affected software of CVE-2020-20218?
The affected software of CVE-2020-20218 is MikroTik RouterOS version 6.44.6 (long-term tree).
3
What is the vulnerability type of CVE-2020-20218?
CVE-2020-20218 is a memory corruption vulnerability.
4
How can an attacker exploit CVE-2020-20218?
An authenticated remote attacker can cause a Denial of Service by exploiting the memory corruption vulnerability in the /nova/bin/traceroute process.
5
Are there any references available for CVE-2020-20218?
Yes, references for CVE-2020-20218 can be found at: [link1](https://seclists.org/fulldisclosure/2020/May/30), [link2](https://seclists.org/fulldisclosure/2021/May/1).