First published: Tue Jul 13 2021(Updated: )
Mikrotik RouterOs before stable version 6.47 suffers from a memory corruption vulnerability in the /nova/bin/lcdstat process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference). NOTE: this is different from CVE-2020-20253 and CVE-2020-20254. All four vulnerabilities in the /nova/bin/lcdstat process are discussed in the CVE-2020-20250 github.com/cq674350529 reference.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <6.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-20250 is a memory corruption vulnerability in the /nova/bin/lcdstat process of Mikrotik RouterOS before version 6.47.
An authenticated remote attacker can exploit CVE-2020-20250 to cause a Denial of Service (NULL pointer dereference) on MikroTik RouterOS.
CVE-2020-20250 has a severity rating of 6.5 (Medium).
Upgrade your MikroTik RouterOS to version 6.47 or later to mitigate CVE-2020-20250.
You can find more information about CVE-2020-20250 on the GitHub repository and the MikroTik website.