CVE-2020-20227: Medium severity mikrotik routeros vulnerability
Published May 18, 2021
·Updated
Mikrotik RouterOs stable 6.47 suffers from a memory corruption vulnerability in the /nova/bin/diskd process. An authenticated remote attacker can cause a Denial of Service due to invalid memory access.
Affected Software
1 affected component
Mikrotik RouterOS=6.47
Event History
May 18, 2021
CVE Published
via MITRE·07:10 PM
Data Sourced
via MITRE·07:10 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20227?
CVE-2020-20227 is a memory corruption vulnerability in Mikrotik RouterOs stable 6.47.
2
How severe is CVE-2020-20227?
CVE-2020-20227 has a severity rating of 6.5, which is considered medium.
3
Who is affected by CVE-2020-20227?
Users of Mikrotik RouterOs stable 6.47 are affected by CVE-2020-20227.
4
How can an attacker exploit CVE-2020-20227?
An authenticated remote attacker can exploit CVE-2020-20227 to cause a Denial of Service by triggering invalid memory access.
5
Is there a fix available for CVE-2020-20227?
Yes, it is recommended to update to a version of Mikrotik RouterOs that is not affected by CVE-2020-20227.