nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2019-3981 CVE-2019-3981
LOW
Record summary
CVE-2019-3981 has a selected CVSS score of 3.7 (low).
Description
MikroTik Winbox 3.20 and below is vulnerable to man in the middle attacks. A man in the middle can downgrade the client's authentication protocol and recover the user's username and MD5 hashed password.
Description source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
WinBoxBrowse MikroTik / WinBox | CVE List | Winbox 3.20 and below. | affected |
References
2tenable.com
https://www.tenable.com/security/research/tra-2020-01