Denial of Service Vulnerability in MikroTik RouterOS
CVE-2022-36522

6.5MEDIUM

Key Information:

Vendor

Mikrotik

Status
Vendor
CVE Published:
26 August 2022

What is CVE-2022-36522?

MikroTik RouterOS versions up to stable v6.48.3 contain a vulnerability in the /advanced-tools/nova/bin/netwatch component, where an assertion failure can be triggered by sending specially crafted packets. This issue can lead to a Denial of Service (DoS), disrupting network operations and affecting the availability of the router. It is crucial for users to implement necessary updates and monitor their devices to prevent potential exploitation.

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.