CVE-2024-54772

An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.
Configurations

No configuration.

History

24 Feb 2025, 16:15

Type Values Removed Values Added
Summary
  • (es) Se descubrió un problema en el servicio Winbox de MikroTik RouterOS v6.43 a v7.16.1. Una discrepancia en los tiempos de respuesta entre los intentos de conexión realizados con un nombre de usuario válido y aquellos con un nombre de usuario no válido permite a los atacantes realizar una enumeración de cuentas válidas.
Summary (en) An issue was discovered in the Winbox service of MikroTik RouterOS v6.43 through v7.16.1. A discrepancy in response times between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts. (en) An issue was discovered in the Winbox service of MikroTik RouterOS long-term release v6.43.13 through v6.49.13 and stable v6.43 through v7.17.2. A patch is available in the stable release v6.49.18. A discrepancy in response size between connection attempts made with a valid username and those with an invalid username allows attackers to enumerate for valid accounts.

12 Feb 2025, 22:15

Type Values Removed Values Added
CWE CWE-208
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4

11 Feb 2025, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-02-11 23:15

Updated : 2025-02-24 16:15


NVD link : CVE-2024-54772

Mitre link : CVE-2024-54772

CVE.ORG link : CVE-2024-54772


JSON object : View

Products Affected

No product.

CWE
CWE-208

Observable Timing Discrepancy