MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack.
oryginał ENCVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:NMikrotik Winbox
OSMikrotik< 3.21
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
Path Traversal
Powiązane podatności
CVE-2020-5721MEDIUM5.5ten sam produkt
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file...
CVE-2019-3981LOW3.7ten sam produkt
MikroTik Winbox w wersji 3.20 i niższych jest podatny na ataki man in the middle. Atakujący pośrodkujący połąc...
CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓ten sam vendor
MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)
CVE-2018-7445CRITICAL9.8⚠ KEVPL ✓ten sam vendor
MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)
CVE-2023-30799CRITICAL9.1PL ✓ten sam vendor
MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE