#VU18951 Man-in-the-Middle (MitM) attack in MikroTik RouterOS - CVE-2018-10066
Published: July 1, 2019
MikroTik RouterOS
MikroTik
Description
The vulnerability allows a remote attacker to perform man-in-the-middle (MitM) attack.
The vulnerability exists due to missing OpenVPN server certificate verification. A remote attacker can perform MitM attack and trick the affected device to connect to a malicious OpenVPN server.
Successful exploitation of this vulnerability may allow an attacker to gain unauthorized access to a local network, behind the Mikrotik router.