Mikrotik RouterOS before 6.44.5 (long-term release tree) is vulnerable to stack exhaustion. By sending a crafted HTTP request, an authenticated remote attacker can crash the HTTP server via recursive parsing of JSON. Malicious code cannot be injected.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: mitre
Published: 2019-07-26T12:13:50
Updated: 2024-08-05T00:05:43.995Z
Reserved: 2019-07-18T00:00:00
Link: CVE-2019-13955
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2019-07-26T13:15:12.910
Modified: 2020-08-24T17:37:01.140
Link: CVE-2019-13955
Redhat
No data.