| CVE | CVE-2020-20021 |
|---|---|
| Severity | HIGH · CVSS 3.1 7.5 |
| Weakness | CWE-400 |
| Affected versions | not yet announced |
| Fixed version | not yet announced |
| Actively exploited | No, as of the date of this article |
| CISA Advisory | none |
| Published | 2023-07-12 |
What is the CVE-2020-20021 vulnerability?
CVE-2020-20021 is a flaw that allows an attacker to cause a denial of service through a misconfiguration in the SSH daemon. The vulnerability is classified as “Uncontrolled Resource Consumption” (CWE-400). The CVSS v3.1 score assigned by the NVD is 7.5 (High), with vector AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H, indicating that the attack is remote, requires no authentication or user interaction, and has a high impact on availability.
Which RouterOS versions are vulnerable?
The official description states that MikroTik Router v6.46.3 and earlier versions are affected. Specific fixed versions have not yet been announced in the available data.
Is my router at risk?
A router is exposed if the SSH service is active and reachable from untrusted networks, such as the Internet or uncontrolled network segments. If the SSH server is configured to accept connections only from the internal administration network or if it is disabled, the risk of remote exploitation is significantly reduced.
Is the CVE-2020-20021 vulnerability actively exploited?
As of the date of this article, there is no evidence that the vulnerability is being actively exploited. It is not present in the CISA KEV catalog, and ENISA does not report it as exploited.
How to protect the router from CVE-2020-20021?
The primary mitigation is to update the firmware to a version later than v6.46.3, if available. Alternatively or additionally, it is advisable to restrict access to the SSH service to the trusted administration network only via firewall filters, or to disable it completely if not required for remote management.
Which RouterOS commands are needed to mitigate CVE-2020-20021?
Temporary mitigation: ssh service
The flaw concerns the router’s SSH server. It must be made reachable only from the administration network, or turned off if you do not use it.
/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24
Update RouterOS
The only definitive fix is the update. Save the configuration first; the installation will reboot the router.
# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade
Frequently asked questions
What is the CVSS score for CVE-2020-20021?
The CVSS v3.1 score for CVE-2020-20021 is 7.5, classified as High severity by the NVD.
Does CVE-2020-20021 require authentication to be exploited?
No, CVE-2020-20021 does not require authentication or user interaction to be exploited, according to the provided CVSS vector.
Which RouterOS services are involved in CVE-2020-20021?
The service involved in CVE-2020-20021 is the router’s SSH server.
Is the CVE-2020-20021 vulnerability present in the CISA KEV catalog?
No, CVE-2020-20021 is not present in the CISA KEV catalog and is not known to be actively exploited.



