Vulnerability Description
An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SUP-12964.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Mikrotik | Routeros | >= 6.41.3, <= 6.46.5 |
Related Weaknesses (CWE)
References
- https://github.com/botlabsDev/CVE-2020-11881ExploitThird Party Advisory
- https://mikrotik.comVendor Advisory
- https://github.com/botlabsDev/CVE-2020-11881ExploitThird Party Advisory
- https://mikrotik.comVendor Advisory
FAQ
What is CVE-2020-11881?
CVE-2020-11881 is a vulnerability with a CVSS score of 7.5 (HIGH). An array index error in MikroTik RouterOS 6.41.3 through 6.46.5, and 7.x through 7.0 Beta5, allows an unauthenticated remote attacker to crash the SMB server via modified setup-request packets, aka SU...
How severe is CVE-2020-11881?
CVE-2020-11881 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-11881?
Check the references section above for vendor advisories and patch information. Affected products include: Mikrotik Routeros.