CVE-2020-20219: Null Pointer Dereference
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/igmp-proxy process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20219?
CVE-2020-20219 is a memory corruption vulnerability in the /nova/bin/igmp-proxy process of Mikrotik RouterOs 6.44.6 (long-term tree) that can be exploited by an authenticated remote attacker to cause a Denial of Service (NULL pointer dereference).
How severe is CVE-2020-20219?
CVE-2020-20219 has a severity rating of 6.5 (medium).
What software versions are affected by CVE-2020-20219?
Mikrotik RouterOs 6.44.6 (long-term tree) is affected by CVE-2020-20219.
How can CVE-2020-20219 be exploited?
An authenticated remote attacker can exploit CVE-2020-20219 by manipulating the /nova/bin/igmp-proxy process, causing a Denial of Service (NULL pointer dereference).
Are there any references related to CVE-2020-20219?
Yes, you can find more information about CVE-2020-20219 at the following references: [MikroTik website](https://mikrotik.com/) and [Full Disclosure mailing list](https://seclists.org/fulldisclosure/2021/May/2).