CVE-2019-13074

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
03/07/2019
Last modified:
24/08/2020

Description

A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:*:*:*:* 6.44.3 (including)
cpe:2.3:h:mikrotik:ccr1009-7g-1c-1s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1009-7g-1c-1s\+pc:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1009-7g-1c-pc:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1016-12g:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1016-12s-1s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-12g-4s:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-12g-4s-em:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-8g-2s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1036-8g-2s\+em:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:ccr1072-1g-8s\+:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_lite:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_poe:-:*:*:*:*:*:*:*
cpe:2.3:h:mikrotik:hex_poe_lite:-:*:*:*:*:*:*:*