First published: Wed Jul 07 2021(Updated: )
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /nova/bin/user process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <6.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20225 is a vulnerability in Mikrotik RouterOs before version 6.47 that allows an authenticated remote attacker to cause a denial of service (DoS) by exploiting an assertion failure in the /nova/bin/user process.
CVE-2020-20225 affects Mikrotik RouterOs versions prior to 6.47 (stable tree).
The severity of CVE-2020-20225 is rated as medium, with a severity value of 6.5.
An attacker can exploit CVE-2020-20225 by sending a crafted packet to the /nova/bin/user process.
Yes, updating Mikrotik RouterOs to version 6.47 or newer will fix the CVE-2020-20225 vulnerability.