A vulnerability in MikroTik Version 6.38.5 could allow an unauthenticated remote attacker to exhaust all available CPU via a flood of UDP packets on port 500 (used for L2TP over IPsec), preventing the affected router from accepting new connections; all devices will be disconnected from the router and all logs removed automatically.
| Software | From | Fixed in |
|---|---|---|
| mikrotik / routeros | 6.38.5 | 6.38.5.x |