CVE-2020-20211
בינונית 6.5
תיאור (מקור, אנגלית)
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
מדדים
- CVSS 3.1
-
6.5 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H - EPSS — סבירות ניצול
- 3% (אחוזון 100) נכון ל-8/10/2026
- CWE
- CWE-617
מוצרים מושפעים
mikrotik: routeros
קישורים
- https://mikrotik.com/ Vendor Advisory
- https://mikrotik.com/ Vendor Advisory
- http://seclists.org/fulldisclosure/2021/May/0 ExploitMailing ListThird Party Advisory
- http://seclists.org/fulldisclosure/2021/May/0 ExploitMailing ListThird Party Advisory
- https://seclists.org/fulldisclosure/2020/Apr/7
- https://seclists.org/fulldisclosure/2020/Jan/12