CVE-2019-13074
A vulnerability in the FTP daemon on MikroTik routers through 6.44.3 could allow remote attackers to exhaust all available memory, causing the device to reboot because of uncontrolled resource management.
Published:Jul 3, 2019
Last Modified:Nov 21, 2024
EPS:Jul 3, 2019
EPSS Score:0.0082
CVSS Score:7.5
Affected Products
Vendor
Product
Action
Vendor
Mikrotik
Product
Ccr1009-7g-1c-1s\+
Mikrotik
Ccr1009-7g-1c-1s\+
Vendor
Mikrotik
Product
Ccr1009-7g-1c-1s\+pc
Mikrotik
Ccr1009-7g-1c-1s\+pc
Vendor
Mikrotik
Product
Ccr1009-7g-1c-pc
Mikrotik
Ccr1009-7g-1c-pc
Vendor
Mikrotik
Product
Ccr1016-12g
Mikrotik
Ccr1016-12g
Vendor
Mikrotik
Product
Ccr1016-12s-1s\+
Mikrotik
Ccr1016-12s-1s\+
Vendor
Mikrotik
Product
Ccr1036-12g-4s
Mikrotik
Ccr1036-12g-4s
Vendor
Mikrotik
Product
Ccr1036-12g-4s-em
Mikrotik
Ccr1036-12g-4s-em
Vendor
Mikrotik
Product
Ccr1036-8g-2s\+
Mikrotik
Ccr1036-8g-2s\+
Vendor
Mikrotik
Product
Ccr1036-8g-2s\+em
Mikrotik
Ccr1036-8g-2s\+em
Vendor
Mikrotik
Product
Ccr1072-1g-8s\+
Mikrotik
Ccr1072-1g-8s\+
Vendor
Mikrotik
Product
Hex
Mikrotik
Hex
Vendor
Mikrotik
Product
Hex Lite
Mikrotik
Hex Lite
Vendor
Mikrotik
Product
Hex Poe
Mikrotik
Hex Poe
Vendor
Mikrotik
Product
Hex Poe Lite
Mikrotik
Hex Poe Lite
Vendor
Mikrotik
Product
Hex S
Mikrotik
Hex S
Vendor
Mikrotik
Product
Powerbox
Mikrotik
Powerbox
Vendor
Mikrotik
Product
Powerbox Pro
Mikrotik
Powerbox Pro
Vendor
Mikrotik
Product
Rb1100ahx4
Mikrotik
Rb1100ahx4
Vendor
Mikrotik
Product
Rb2011il-in
Mikrotik
Rb2011il-in
Vendor
Mikrotik
Product
Rb2011il-rm
Mikrotik
Rb2011il-rm
Vendor
Mikrotik
Product
Rb2011ils-in
Mikrotik
Rb2011ils-in
Vendor
Mikrotik
Product
Rb2011uias-in
Mikrotik
Rb2011uias-in
Vendor
Mikrotik
Product
Rb2011uias-rm
Mikrotik
Rb2011uias-rm
Vendor
Mikrotik
Product
Rb3011uias-rm
Mikrotik
Rb3011uias-rm
Vendor
Mikrotik
Product
Rb4011igs\+rm
Mikrotik
Rb4011igs\+rm
Vendor
Mikrotik
Product
Routeros
Mikrotik
Routeros
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
