CVE-2017-6297

MEDIUM

Mikrotik Routeros - Missing Encryption

Title source: rule

Description

The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.

Scores

CVSS v3 5.9
EPSS 0.0011
EPSS Percentile 29.0%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-311
Status published

Affected Products (3)

mikrotik/routeros
mikrotik/routeros
n/a/n/a

Timeline

Published Feb 27, 2017
Tracked Since Feb 18, 2026