CVE-2020-20248: Medium severity mikrotik routeros vulnerability
Mikrotik RouterOs before stable 6.47 suffers from an uncontrolled resource consumption in the memtest process. An authenticated remote attacker can cause a Denial of Service due to overloading the systems CPU.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-20248?
CVE-2020-20248 is a vulnerability in Mikrotik RouterOs before stable 6.47 that allows an authenticated remote attacker to cause a Denial of Service by overloading the system's CPU.
How severe is CVE-2020-20248?
CVE-2020-20248 has a severity score of 6.5, which is considered medium.
Which version of Mikrotik RouterOs is affected by CVE-2020-20248?
Mikrotik RouterOs version 6.47 and earlier are affected by CVE-2020-20248.
How can an attacker exploit CVE-2020-20248?
An attacker needs to be authenticated to exploit CVE-2020-20248 and can cause a Denial of Service by overloading the system's CPU.
Is there a fix available for CVE-2020-20248?
Yes, fixing CVE-2020-20248 requires updating Mikrotik RouterOs to a stable version 6.47 or later.