← back
CVE-2020-5720

CVE-2020-5720

EPSS 1.1%CWE-22
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.1%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
06 Feb 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
MikroTik WinBox before 3.21 is vulnerable to a path traversal vulnerability that allows creation of arbitrary files wherevere WinBox has write permissions. WinBox is vulnerable to this attack if it connects to a malicious endpoint or if an attacker mounts a man in the middle attack.
Affected products
n/a · MikroTik WinBox