Описание
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
Ссылки
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ExploitThird Party AdvisoryVDB Entry
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
- ExploitMailing ListThird Party Advisory
Уязвимые конфигурации
Конфигурация 1
cpe:2.3:a:taskautomation:carbonftp:1.4:*:*:*:*:*:*:*
EPSS
Процентиль: 33%
0.00126
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-327
Связанные уязвимости
CVSS3: 5.5
github
больше 3 лет назад
CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.
EPSS
Процентиль: 33%
0.00126
Низкий
5.5 Medium
CVSS3
2.1 Low
CVSS2
Дефекты
CWE-327