CVE-2020-5721 Vulnerability Details

  /     /     /  

CVE-2020-5721 Metadata Quick Info

CVE Published: 15/04/2020 | CVE Updated: 04/08/2024 | CVE Year: 2020
Source: tenable | Vendor: n/a | Product: MikroTik WinBox
Status : PUBLISHED

CVE-2020-5721 Description

MikroTik WinBox 3.22 and below stores the user\'s cleartext password in the settings.cfg.viw configuration file when the Keep Password field is set and no Master Password is set. Keep Password is set by default and, by default Master Password is not set. An attacker with access to the configuration file can extract a username and password to gain access to the router.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-260
CWE Name: CWE-260
Source: n/a

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).