CVE-2021-36613: Null Pointer Dereference
Published May 11, 2022
·Updated
Mikrotik RouterOs before stable 6.48.2 suffers from a memory corruption vulnerability in the ptp process. An authenticated remote attacker can cause a Denial of Service (NULL pointer dereference).
Affected Software
1 affected component
Mikrotik RouterOS<6.48.2
Remediation
Patch Available
Event History
May 11, 2022
CVE Published
via MITRE·05:34 PM
Data Sourced
via MITRE·05:34 PM
Description
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2021-36613.
2
What is the title of the vulnerability?
The title of the vulnerability is 'Mikrotik RouterOs before stable 6.48.2 memory corruption vulnerability in the ptp process'.
3
What is the severity of CVE-2021-36613?
The severity of CVE-2021-36613 is medium with a CVSS score of 6.5.
4
How does CVE-2021-36613 affect MikroTik RouterOS?
CVE-2021-36613 affects MikroTik RouterOS versions prior to 6.48.2.
5
How can an attacker exploit CVE-2021-36613?
An authenticated remote attacker can exploit CVE-2021-36613 to cause a Denial of Service (NULL pointer dereference).