Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2374-xjj3-xj59

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.

EPSS

Процентиль: 57%
0.00347
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
nvd
больше 6 лет назад

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.

EPSS

Процентиль: 57%
0.00347
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-522