7.5
CVSSv3

CVE-2020-11881

Published: 14/09/2020 Updated: 18/09/2020
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
CVSS v3 Base Score: 7.5 | Impact Score: 3.6 | Exploitability Score: 3.9
VMScore: 445
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

An array index error in MikroTik RouterOS 6.41.3 up to and including 6.46.5, and 7.x up to and including 7.0 Beta5, allows an unauthenticated remote malicious user to crash the SMB server via modified setup-request packets, aka SUP-12964.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

mikrotik routeros

mikrotik routeros 7.0

Github Repositories

CVE-2020-11881: unauthenticated remote DoS for MikroTik SMB service.

CVE-2020-11881 MikroTik SMB Remote Denial of Service (DoS) This report describes CVE-2020-11881, an unauthenticated remote DoS for MikroTik's SMB service running on RouterOs The vulnerability allows an attacker to crash the running SMB service and was responsible disclosed to security<@>mikrotikcom on 06042020 The Server Message Block (SMB) protocol was