4.3
CVE-2019-16116
- EPSS 3.01%
- Veröffentlicht 02.10.2019 16:15:14
- Zuletzt bearbeitet 21.11.2024 04:30:04
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
EnterpriseDT CompleteFTP Server prior to version 12.1.3 is vulnerable to information exposure in the Bootstrap.log file. This allows an attacker to obtain the administrator password hash.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Enterprisedt ≫ Completeftp Server Version < 12.1.3
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.01% | 0.861 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 4.3 | 2.8 | 1.4 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
CWE-327 Use of a Broken or Risky Cryptographic Algorithm
The product uses a broken or risky cryptographic algorithm or protocol.
CWE-532 Insertion of Sensitive Information into Log File
The product writes sensitive information to a log file.