First published: Wed Jul 21 2021(Updated: )
Mikrotik RouterOs before 6.47 (stable tree) suffers from an assertion failure vulnerability in the /ram/pckg/security/nova/bin/ipsec process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
MikroTik RouterOS | <6.47 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2020-20262.
The severity of CVE-2020-20262 is medium with a CVSS score of 6.5.
MikroTik RouterOS versions up to (but not including) 6.47 are affected.
An authenticated remote attacker can cause a Denial of Service (DoS) due to an assertion failure via a crafted packet.
Yes, you can find references for CVE-2020-20262 at the following links: [Link 1](https://github.com/cq674350529/pocs_slides/blob/master/pocs/MikroTik/vul_ipsec/README.md), [Link 2](https://seclists.org/fulldisclosure/2021/May/2).