7.8

CVE-2020-10364

Exploit
The SSH daemon on MikroTik routers through v6.44.3 could allow remote attackers to generate CPU activity, trigger refusal of new authorized connections, and cause a reboot via connect and write system calls, because of uncontrolled resource management.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
MikrotikRouteros Version <= 6.44.3
   MikrotikCcr1009-7g-1c-1s+ Version-
   MikrotikCcr1009-7g-1c-1s+pc Version-
   MikrotikCcr1009-7g-1c-pc Version-
   MikrotikCcr1016-12g Version-
   MikrotikCcr1016-12s-1s+ Version-
   MikrotikCcr1036-12g-4s Version-
   MikrotikCcr1036-12g-4s-em Version-
   MikrotikCcr1036-8g-2s+ Version-
   MikrotikCcr1036-8g-2s+em Version-
   MikrotikCcr1072-1g-8s+ Version-
   MikrotikHex Version-
   MikrotikHex Lite Version-
   MikrotikHex Poe Version-
   MikrotikHex Poe Lite Version-
   MikrotikHex S Version-
   MikrotikPowerbox Version-
   MikrotikPowerbox Pro Version-
   MikrotikRb1100ahx4 Version-
   MikrotikRb1100ahx4 Version- Editiondude
   MikrotikRb2011il-in Version-
   MikrotikRb2011il-rm Version-
   MikrotikRb2011ils-in Version-
   MikrotikRb2011uias-in Version-
   MikrotikRb2011uias-rm Version-
   MikrotikRb3011uias-rm Version-
   MikrotikRb4011igs+rm Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.66% 0.843
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
NIST 7.8 10 6.9
AV:N/AC:L/Au:N/C:N/I:N/A:C
CWE-770 Allocation of Resources Without Limits or Throttling

The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

https://packetstormsecurity.com/files/156790/Microtik-SSH-Daemon-6.44.3-Denial-Of-Service.html
Third Party Advisory
Exploit
VDB Entry
Mitigation
https://www.exploit-db.com/exploits/48228
Third Party Advisory
Exploit
VDB Entry
Mitigation