CVE-2020-5721: Medium severity Mikrotik WinBox vulnerability
MikroTik WinBox 3.22 and below stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Password is not set. An attacker with access to the configuration file can extract a username and password to gain access to the router.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-5721.
What is the severity of CVE-2020-5721?
The severity of CVE-2020-5721 is medium with a score of 5.5.
What is the affected software?
The affected software is MikroTik WinBox version 3.22 and below.
How does CVE-2020-5721 store user passwords?
CVE-2020-5721 stores the user's cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set.
Is there a fix for CVE-2020-5721?
Yes, updating MikroTik WinBox to a version above 3.22 will fix CVE-2020-5721 vulnerability.