Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2018-16791

Опубликовано: 05 дек. 2018
Источник: nvd
CVSS3: 9.8
CVSS2: 5
EPSS Низкий

Описание

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:solarwinds:sftp\/scp_server:*:*:*:*:*:*:*:*
Версия до 20180910 (включая)

EPSS

Процентиль: 57%
0.00347
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-522

Связанные уязвимости

CVSS3: 9.8
github
около 3 лет назад

In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords for potentially privileged accounts. This also grants the attacker an ability to backdoor the server.

EPSS

Процентиль: 57%
0.00347
Низкий

9.8 Critical

CVSS3

5 Medium

CVSS2

Дефекты

CWE-522