QID 730288
Date Published: 2021-12-06
QID 730288: MikroTik RouterOS Open Virtual Private Network (OpenVPN) Server Certificate Verification Vulnerability
MikroTik RouterOS is the operating system of MikroTik RouterBOARD hardware.
Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's internal network (for example, at site-to-site tunnels).
Affected Versions:
MikroTik RouterOS 6.41.4
QID Detection Logic(Unauthenticated):
It uses page source h1 tag to detect vulnerable version of MikroTik RouterOS.
Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malicious OpenVPN server. This may allow the attacker to gain access to the client's internal network (for example, at site-to-site tunnels).
NA
CVEs related to QID 730288
| Advisory ID | Software | Component | Link |
|---|