CVE-2019-3981

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
14/01/2020
Last modified:
22/10/2020

Description

MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:* 6.43 (excluding)
cpe:2.3:o:mikrotik:winbox:*:*:*:*:*:*:*:* 3.20 (excluding)


References to Advisories, Solutions, and Tools