The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
References
Link | Resource |
---|---|
https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html | Exploit Mitigation Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/48228 | Exploit Mitigation Third Party Advisory VDB Entry |
https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html | Exploit Mitigation Third Party Advisory VDB Entry |
https://www.exploit-db.com/exploits/48228 | Exploit Mitigation Third Party Advisory VDB Entry |
Configurations
Configuration 1 (hide)
AND |
|
History
21 Nov 2024, 04:55
Type | Values Removed | Values Added |
---|---|---|
References | () https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html - Exploit, Mitigation, Third Party Advisory, VDB Entry | |
References | () https://www.exploit-db.com/exploits/48228 - Exploit, Mitigation, Third Party Advisory, VDB Entry |
Information
Published : 2020-03-23 16:15
Updated : 2024-11-21 04:55
NVD link : CVE-2020-10364
Mitre link : CVE-2020-10364
CVE.ORG link : CVE-2020-10364
JSON object : View
Products Affected
mikrotik
- ccr1009-7g-1c-1s\+pc
- powerbox_pro
- rb2011il-rm
- hex_poe
- hex_lite
- rb2011uias-in
- routeros
- ccr1036-8g-2s\+
- powerbox
- ccr1016-12g
- ccr1036-12g-4s
- hex_poe_lite
- ccr1036-12g-4s-em
- hex_s
- ccr1072-1g-8s\+
- ccr1009-7g-1c-1s\+
- rb2011ils-in
- ccr1016-12s-1s\+
- hex
- rb2011il-in
- ccr1036-8g-2s\+em
- rb3011uias-rm
- rb2011uias-rm
- ccr1009-7g-1c-pc
- rb4011igs\+rm
- rb1100ahx4
CWE
CWE-770
Allocation of Resources Without Limits or Throttling