MEDIUM🇵🇱 Wersja polska

CVE-2020-5720

CVSS 5.9v3.1pub. 2020-02-06upd. 2024-11-21

MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack.

CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N
  • Mikrotik Winbox

    OS
    Mikrotik
    < 3.21
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Path Traversal
CWE
References

Related vulnerabilities

CVE-2020-5721MEDIUM5.5same product

MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file...

CVE-2019-3981LOW3.7same product

MikroTik Winbox w wersji 3.20 i niższych jest podatny na ataki man in the middle. Atakujący pośrodkujący połąc...

CVE-2018-14847CRITICAL9.1⚠ KEVPL ✓same vendor

MikroTik RouterOS — path traversal w interfejsie WinBox (odczyt/zapis plików)

CVE-2018-7445CRITICAL9.8⚠ KEVPL ✓same vendor

MikroTik RouterOS SMB — buffer overflow przed uwierzytelnieniem (RCE)

CVE-2023-30799CRITICAL9.1PL ✓same vendor

MikroTik RouterOS — privilege escalation admin do super-admin z możliwością RCE