CVE-2020-20222: Null Pointer Dereference
Mikrotik RouterOs 6.44.6 (long-term tree) suffers from a memory corruption vulnerability in the /nova/bin/sniffer process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20222?
CVE-2020-20222 is a memory corruption vulnerability in the Mikrotik RouterOS 6.44.6 (long-term tree) in the /nova/bin/sniffer process, which can be exploited by an authenticated remote attacker to cause a Denial of Service (NULL pointer dereference).
How severe is CVE-2020-20222?
CVE-2020-20222 has a severity value of 6.5, which is classified as medium severity.
What is the affected software version?
The affected software version is Mikrotik RouterOS 6.44.6 (long-term tree).
How can an attacker exploit CVE-2020-20222?
An authenticated remote attacker can exploit CVE-2020-20222 by leveraging the vulnerability in the /nova/bin/sniffer process to cause a Denial of Service (NULL pointer dereference).
Are there any references for CVE-2020-20222?
Yes, you can find references for CVE-2020-20222 at the following links: [Packet Storm Security](http://packetstormsecurity.com/files/162513/Mikrotik-RouterOS-6.46.5-Memory-Corruption-Assertion-Failure.html), [SecLists Full Disclosure](http://seclists.org/fulldisclosure/2021/May/15), [MikroTik](https://mikrotik.com/).