PT-2020-10925 · Mikrotik · Winbox+1

Published

2020-01-14

·

Updated

2020-10-22

·

CVE-2019-3981

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions MikroTik Winbox versions 3.20 and below
Description The issue allows a man-in-the-middle attacker to downgrade the client's authentication protocol, potentially leading to the recovery of the user's username and MD5 hashed password.
Recommendations For versions 3.20 and below, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-3981

Affected Products

Mikrotik Routeros
Winbox