PT-2020-12915 · Mikrotik · Routeros+1

Published

2020-09-14

·

Updated

2020-09-18

·

CVE-2020-11881

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions MikroTik RouterOS versions 6.41.3 through 6.46.5 MikroTik RouterOS versions 7.x through 7.0 Beta5
Description The issue is related to an array index error that can be exploited by an unauthenticated remote attacker to crash the SMB server. This is achieved by sending modified setup-request packets.
Recommendations For versions 6.41.3 through 6.46.5, update to a version outside of this range to resolve the issue. For versions 7.x through 7.0 Beta5, update to a version later than 7.0 Beta5 to resolve the issue. As a temporary workaround, consider restricting access to the SMB server until a patch is available.

Exploit

Fix

Improper Validation of Array Index

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-11881

Affected Products

Mikrotik Routeros
Routeros