CVE-2020-20246: Medium severity mikrotik routeros vulnerability
Published May 18, 2021
·Updated
Mikrotik RouterOs stable 6.46.3 suffers from a memory corruption vulnerability in the mactel process. An authenticated remote attacker can cause a Denial of Service due to improper memory access.
Affected Software
1 affected component
Mikrotik RouterOS=6.46.3
Event History
May 18, 2021
CVE Published
via MITRE·07:11 PM
Data Sourced
via MITRE·07:11 PM
Description
Frequently Asked Questions
1
What is CVE-2020-20246?
CVE-2020-20246 is a memory corruption vulnerability in the mactel process of MikroTik RouterOS stable version 6.46.3.
2
How severe is CVE-2020-20246?
CVE-2020-20246 has a severity rating of 6.5 (medium).
3
How does CVE-2020-20246 affect MikroTik RouterOS?
CVE-2020-20246 can cause a Denial of Service (DoS) due to improper memory access in MikroTik RouterOS.
4
How can an attacker exploit CVE-2020-20246?
An authenticated remote attacker can exploit CVE-2020-20246 to trigger the memory corruption vulnerability and cause a Denial of Service.
5
Is there a fix for CVE-2020-20246?
It is recommended to update MikroTik RouterOS to a version that does not suffer from the memory corruption vulnerability.