The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2017-15358 | The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-05T15:25:48.822Z
Reserved: 2017-02-23T00:00:00.000Z
Link: CVE-2017-6297
No data.
Status : Deferred
Published: 2017-02-27T07:59:00.347
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-6297
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD