Community discussions

MikroTik App
 
ujemvi
just joined
Topic Author
Posts: 13
Joined: Wed May 16, 2012 9:37 pm

Mikrotik and CVE-2020-0601

Wed Jan 15, 2020 2:21 pm

Hi guys!

I know almost nothing about vulnerabilities and that world, but I'd like to know if Mikrotik is under fire regarding CVE-2020-0601.
I'm seeing some noise about that vulnerability.
Should I be asking for some maintenance windows for a software update in my devices?

Thanks!
 
User avatar
normis
MikroTik Support
MikroTik Support
Posts: 26377
Joined: Fri May 28, 2004 11:04 am
Location: Riga, Latvia

Re: Mikrotik and CVE-2020-0601

Wed Jan 15, 2020 2:38 pm

hmm?
flaw exists in crypt32.dll, the Microsoft Cryptographic Application Programming Interface (CryptoAPI)
 
r00t
Long time Member
Long time Member
Posts: 674
Joined: Tue Nov 28, 2017 2:14 am

Re: Mikrotik and CVE-2020-0601

Wed Jan 15, 2020 2:53 pm

This only affects Windows 10 and certificate verification by crypt32.dll. So ROS is completely unaffected and only theoretical possibility would be stuff like verifying of automatic winbox updates. But all this is now moot point, it was already patched yesterday by Microsoft and it only impacted Windows 10...
 
himvas
newbie
Posts: 28
Joined: Fri Apr 15, 2016 9:26 am

Re: Mikrotik and CVE-2020-0601

Wed Jan 15, 2020 11:22 pm

Not only Win10 but all prev WinNT bases Windows (2000, XP, 7, 8).
 
User avatar
ingdaka
Trainer
Trainer
Posts: 452
Joined: Thu Aug 30, 2012 3:06 pm
Location: Albania
Contact:

Re: Mikrotik and CVE-2020-0601

Wed Jan 15, 2020 11:25 pm

Router OS is not Microsoft Windows based and is not .NET coded!

Who is online

Users browsing this forum: dandu and 106 guests