CVE-2020-20231: Null Pointer Dereference
Published Jul 14, 2021
·Updated
Mikrotik RouterOs through stable version 6.48.3 suffers from a memory corruption vulnerability in the /nova/bin/detnet process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
1 affected component
Mikrotik RouterOS>=6.44.6<=6.48.3
Event History
Jul 14, 2021
CVE Published
via MITRE·01:53 PM
Data Sourced
via MITRE·01:53 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20231?
CVE-2020-20231 is a memory corruption vulnerability in the MikroTik RouterOS through stable version 6.48.3.
2
How does CVE-2020-20231 affect MikroTik RouterOS?
CVE-2020-20231 can cause a Denial of Service (NULL pointer dereference) in the /nova/bin/detnet process of MikroTik RouterOS.
3
What is the severity of CVE-2020-20231?
CVE-2020-20231 has a severity rating of 6.5 (Medium).
4
How can an authenticated remote attacker exploit CVE-2020-20231?
An authenticated remote attacker can exploit CVE-2020-20231 to cause a Denial of Service by triggering a memory corruption in the /nova/bin/detnet process.
5
Is there a fix available for CVE-2020-20231?
Yes, upgrading MikroTik RouterOS to a version beyond 6.48.3 will fix CVE-2020-20231.