First published: Tue May 18 2021(Updated: )
Mikrotik RouterOs prior to stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/bfd process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <6.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20220 is a memory corruption vulnerability in the /nova/bin/bfd process of MikroTik RouterOS prior to version 6.47, which can be exploited by an authenticated remote attacker to cause a Denial of Service (NULL pointer dereference).
CVE-2020-20220 has a severity score of 6.5, which is considered medium severity.
CVE-2020-20220 can only be exploited by an authenticated remote attacker, so it requires valid credentials to access the vulnerable system.
To mitigate CVE-2020-20220, it is recommended to update MikroTik RouterOS to version 6.47 or newer, as this vulnerability has been fixed in the stable release.
More information about CVE-2020-20220 can be found on the MikroTik website and various security advisory sources such as Packet Storm Security and Full Disclosure mailing list.