Description
Mikrotik RouterOs 6.44.5 (long-term tree) suffers from an assertion failure vulnerability in the /nova/bin/console process. An authenticated remote attacker can cause a Denial of Service due to an assertion failure via a crafted packet.
CVSS breakdown
CVSS 3.1
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected products
- MikroTik / RouterOS6.44.5 – 6.44.5
References
- MISChttps://mikrotik.com/
- MAILING_LISThttps://seclists.org/fulldisclosure/2020/Apr/7
- MAILING_LISThttp://seclists.org/fulldisclosure/2021/May/0
- MAILING_LISThttps://seclists.org/fulldisclosure/2020/Jan/12
Updated 7m ago · 8 sources