CVE
- Id
- 103117
- CVE No.
- CVE-2017-6297
- Status
- Candidate
- Description
- The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
- Phase
- Assigned (20170223)
- Votes
- None (candidate not yet proposed)
- Comments