7.8
CVE-2020-8634
- EPSS 0.43%
- Veröffentlicht 07.03.2020 00:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:09
- Erkennungen
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Wftpserver ≫ Wing Ftp Server Version 6.2.3 SwPlatform linux
Wftpserver ≫ Wing Ftp Server Version 6.2.3 SwPlatform macos
Wftpserver ≫ Wing Ftp Server Version 6.2.3 SwPlatform solaris
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.339 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-281 Improper Preservation of Permissions
The product does not preserve permissions or incorrectly preserves permissions when copying, restoring, or sharing objects, which can cause them to have less restrictive permissions than intended.
https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php