CVE-2020-20021
HIGHMikroTik RouterOS < 6.46.3 - Denial of Service via SSH Daemon Misconfiguration
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2020-20021. PoCs published by FarazPajohan.
AI-analyzed exploit summary This exploit demonstrates an uncontrolled resource consumption vulnerability in MikroTik SSH daemon (v6.44.3 and earlier) by establishing multiple connections and writing null bytes, leading to a denial of service (DoS) via SIGPIPE signal and potential system reboot.
Description
An issue discovered in MikroTik Router v6.46.3 and earlier allows attacker to cause denial of service via misconfiguration in the SSH daemon.
Exploits (1)
This exploit demonstrates an uncontrolled resource consumption vulnerability in MikroTik SSH daemon (v6.44.3 and earlier) by establishing multiple connections and writing null bytes, leading to a denial of service (DoS) via SIGPIPE signal and potential system reboot.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H