7.1
CVE-2021-41637
- EPSS 0.04%
- Veröffentlicht 24.06.2022 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Melag ≫ Ftp Server Version2.2.0.4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.101 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 7.1 | 1.8 | 5.2 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
|
| nvd@nist.gov | 3.6 | 3.9 | 4.9 |
AV:L/AC:L/Au:N/C:P/I:P/A:N
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.