CVE CVE-2020-10364
Severity HIGH · CVSS 3.1 7.5
Weakness CWE-770
Affected versions not yet announced
Fixed version not yet announced
Actively exploited No, as of the date of this article
CISA Advisory none
Published 2020-03-23

What is the CVE-2020-10364 vulnerability?

The vulnerability resides in the SSH daemon of the routers and allows a remote attacker to generate CPU activity, prevent the acceptance of new authorized connections, and cause the device to reboot. This occurs through “connect” and “write” system calls, due to uncontrolled resource management (CWE-770: Allocation of Resources Without Limits or Throttling).

Which RouterOS versions are vulnerable?

The affected versions and the fixed version have not yet been announced. The original description indicates that the issue is present in systems up to and including version 6.44.3.

Is my router at risk?

A router is exposed if the SSH service is active and reachable from untrusted networks, such as the Internet or uncontrolled network segments. If the SSH daemon is disabled or access is restricted exclusively to the internal administration network, the risk of remote exploitation is reduced.

Is the CVE-2020-10364 vulnerability actively exploited?

As of the date of the article, the vulnerability is not listed in the CISA KEV catalog and is not reported as exploited by ENISA. There is no evidence of known active exploitation.

How to protect the router from CVE-2020-10364?

The primary protection consists of updating the operating system to the correct version, if available. Alternatively or additionally, it is necessary to restrict access to the SSH service: disable it if not used, or configure firewall rules to allow access only from the trusted administration network, blocking connections from external networks.

Which RouterOS commands are needed to mitigate CVE-2020-10364?

Temporary mitigation: ssh service

The defect concerns the router’s SSH server. It must be made reachable only from the administration network, or turned off if you do not use it.

/ip service print
# se SSH non serve
/ip service set ssh disabled=yes
# se serve: limitalo alla rete di gestione (sostituisci con la tua)
/ip service set ssh address=192.168.88.0/24

Update RouterOS

The only definitive fix is the update. First, save the configuration; the installation reboots the router.

# 1. salva configurazione e backup
/export file=prima-aggiornamento
/system backup save name=prima-aggiornamento
# 2. scegli il canale (long-term o stable) e controlla la versione disponibile
/system package update set channel=stable
/system package update check-for-updates
# 3. installa: ATTENZIONE, il router si riavvia
/system package update install
# 4. dopo il riavvio, aggiorna anche il firmware (RouterBOOT) e riavvia di nuovo
/system routerboard upgrade

Frequently asked questions

What is the CVSS score for CVE-2020-10364?

CVE-2020-10364 has a CVSS v3.1 score of 7.5, classified as HIGH severity. The vector indicates a network attack with low complexity, no authentication or user interaction required, and high impact on integrity.

Is authentication required to exploit CVE-2020-10364?

No, the CVE-2020-10364 vulnerability does not require authentication. The CVSS vector specifies “PR:N” (Privileges Required: None), indicating that a remote attacker can exploit it without valid credentials.

Does disabling the SSH service eliminate the risk of CVE-2020-10364?

Yes, disabling the SSH daemon removes the attack vector for CVE-2020-10364, as the vulnerability resides specifically in that component. If the service is not active, an attacker cannot interact with the defective code.

Is CVE-2020-10364 listed in the CISA KEV catalog?

No, CVE-2020-10364 is not listed in the CISA KEV (Known Exploited Vulnerabilities) catalog. The “known_exploited” field is indicated as false, and the date of addition to the catalog is not provided.

Official sources