PT-2020-5639 · Mikrotik · Mikrotik Winbox

Published

2020-04-15

·

Updated

2020-04-28

·

CVE-2020-5721

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions MikroTik WinBox versions 3.22 and below
Description The issue is related to insufficient protection of registration data in the settings.cfg.viw configuration file. When the Keep Password field is set and no Master Password is set, the user's cleartext password is stored in this file. By default, Keep Password is enabled, and Master Password is not set. An attacker with access to the configuration file can extract a username and password, allowing them to gain unauthorized access to the router.
Recommendations For MikroTik WinBox versions 3.22 and below, consider setting a Master Password to protect the configuration file and stored credentials. As a temporary workaround, restrict access to the settings.cfg.viw configuration file to minimize the risk of exploitation. Avoid using the default settings for Keep Password and Master Password to prevent cleartext password storage.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-01339
CVE-2020-5721

Affected Products

Mikrotik Winbox