CVE-2019-3981

Severity CVSS v4.0:
Pending analysis
Type:
CWE-300 Channel Accessible by Non-Endpoint
Publication date:
14/01/2020
Last modified:
17/06/2026

Description

MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* 6.43 (excluding)
cpe:2.3:o:mikrotik:winbox:*:*:*:*:*:*:*:* 3.20 (excluding)