---
id: CVE-2017-6297
title: >-
  The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not
  enable IPsec encryption after a reboot, which allows man-in-the-middle
  attackers to view transmitted data unencrypted and gain access to networks on
  the L2TP server…
summary: >-
  The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not
  enable IPsec encryption after a reboot, which allows man-in-the-middle
  attackers to view transmitted data unencrypted and gain access to networks on
  the L2TP server…
severity: medium
cvss: 5.9
cvssVector: 'CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-311
vendor: mikrotik
product: routeros
affected:
  - routeros = 6.37.4
  - routeros = 6.83.3
published: '2017-02-27'
updated: '2026-09-16'
sourceUpdated: '2026-09-16T21:17:05.393'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2017-6297'
references:
  - url: 'http://www.securityfocus.com/bid/96447'
    label: cve@mitre.org
  - url: >-
      https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/
    label: cve@mitre.org
  - url: 'http://www.securityfocus.com/bid/96447'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://blog.milne.it/2017/02/24/mikrotik-routeros-security-vulnerability-l2tp-tunnel-unencrypted-cve-2017-6297/
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - cve.org
epss: 0.00743
epssPercentile: 0.53233
ingestedAt: '2026-09-16T21:05:36.878Z'
---

## Overview

The L2TP Client in MikroTik RouterOS versions 6.38.3 and 6.37.4 does not enable IPsec encryption after a reboot, which allows man-in-the-middle attackers to view transmitted data unencrypted and gain access to networks on the L2TP server by monitoring the packets for the transmitted data and obtaining the L2TP secret.

## Affected

- `routeros = 6.37.4`
- `routeros = 6.83.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
