CVE-2020-10364

The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
References
Link Resource
https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html Exploit Mitigation Third Party Advisory VDB Entry
https://www.exploit-db.com/exploits/48228 Exploit Mitigation Third Party Advisory VDB Entry
Configurations

Configuration 1 (hide)

AND
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:*
OR cpe:2.3:h:mikrotik:ccr1009-7g-1c-1s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1009-7g-1c-1s\+pc:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1009-7g-1c-pc:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1016-12g:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1016-12s-1s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-12g-4s:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-12g-4s-em:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-8g-2s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-8g-2s\+em:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1072-1g-8s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_lite:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_poe:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_poe_lite:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_s:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:powerbox:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:powerbox_pro:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb1100ahx4:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb1100ahx4:-:*:dude:*:*:*:*:*
cpe:2.3:h:mikrotik:rb2011il-in:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb2011il-rm:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb2011ils-in:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb2011uias-in:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb2011uias-rm:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb3011uias-rm:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:rb4011igs\+rm:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2020-03-23 16:15

Updated : 2024-02-28 17:47


NVD link : CVE-2020-10364

Mitre link : CVE-2020-10364

CVE.ORG link : CVE-2020-10364


JSON object : View

Products Affected

mikrotik

  • powerbox_pro
  • ccr1016-12s-1s\+
  • hex
  • rb2011uias-rm
  • rb3011uias-rm
  • hex_s
  • ccr1036-12g-4s
  • rb2011uias-in
  • ccr1036-8g-2s\+
  • ccr1036-12g-4s-em
  • ccr1009-7g-1c-1s\+
  • rb4011igs\+rm
  • hex_poe_lite
  • powerbox
  • ccr1072-1g-8s\+
  • hex_lite
  • ccr1009-7g-1c-pc
  • rb2011ils-in
  • rb2011il-rm
  • ccr1009-7g-1c-1s\+pc
  • ccr1016-12g
  • rb1100ahx4
  • routeros
  • hex_poe
  • ccr1036-8g-2s\+em
  • rb2011il-in
CWE
CWE-770

Allocation of Resources Without Limits or Throttling