PT-2019-3741 · Mikrotik · Routeros+1

Cq674350529

+1

·

Published

2019-07-24

·

Updated

2020-08-24

·

CVE-2019-13954

CVSS v2.0

6.8

Medium

VectorAV:N/AC:L/Au:S/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Mikrotik RouterOS versions prior to 6.44.5
Description The issue is related to memory exhaustion, where an authenticated remote attacker can crash the HTTP server and potentially reboot the system by sending a crafted HTTP request. This can lead to a denial of service. There is no mention of the estimated number of potentially affected devices or real-world incidents.
Recommendations For versions prior to 6.44.5, update to version 6.44.5 or later to resolve the issue. As a temporary workaround, consider restricting access to the HTTP server to minimize the risk of exploitation.

Fix

Allocation of Resources Without Limits

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2019-03997
CVE-2019-13954

Affected Products

Mikrotik Routeros
Routeros