CVE-2017-6297
published 2017-02-27CVE-2017-6297: The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to…
PriorityP428medium5.9CVSS 3.0
AVNACHPRNUINSUCHINAN
EPSS
0.76%
53.3th percentile
The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| mikrotik | routeros | — | — |
| mikrotik | routeros | — | — |
CVSS provenance
nvdv3.05.9MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
MikroTik RouterOS 6.37.4/6.83.3 L2TP Client IPsec 7pk security (BID-96447 / ID 103115)
vuldb·2026-09-17·CVSS 5.9
CVE-2017-6297 [MEDIUM] MikroTik RouterOS 6.37.4/6.83.3 L2TP Client IPsec 7pk security (BID-96447 / ID 103115)
A vulnerability categorized as critical has been discovered in MikroTik RouterOS 6.37.4/6.83.3. This affects an unknown part of the component L2TP Client. The manipulation results in 7pk security features (IPsec).
This vulnerability was named CVE-2017-6297. The attack may be performed from remote. There is no available exploit.
Adding more encryption is recommended.
GHSA
GHSA-8p5m-cg5p-7249: The L2TP Client in MikroTik RouterOS versions 6
ghsa_unreviewed·2022-05-13
CVE-2017-6297 [MEDIUM] CWE-311 GHSA-8p5m-cg5p-7249: The L2TP Client in MikroTik RouterOS versions 6
The L2TP Client in MikroTik RouterOS versions 6.83.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://www.securityfocus.com/bid/96447https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/http://www.securityfocus.com/bid/96447https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/
2017-02-27
Published