An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
Attack Parameters
Impact Assessment
CVSS Vector v3.1
Weakness Type (CWE)
Vulnerable Products 3
| Configuration | From (including) | Up to (excluding) |
|---|---|---|
|
Mikrotik Routeros
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*
|
6.43
|
6.49.18
|
|
Mikrotik Routeros
cpe:2.3:o:mikrotik:routeros:*:*:*:*:ltr:*:*:*
|
6.43.13
|
<= 6.49.13
|
|
Mikrotik Routeros
cpe:2.3:o:mikrotik:routeros:*:*:*:*:-:*:*:*
|
7.1
|
7.18
|