Описание
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
Ссылки
- Third Party Advisory
- Release NotesVendor Advisory
- PatchVendor Advisory
- Third Party Advisory
- Release NotesVendor Advisory
- PatchVendor Advisory
Уязвимые конфигурации
Конфигурация 1Версия до 15.3.2 (исключая)
cpe:2.3:a:solarwinds:serv-u:*:*:*:*:*:*:*:*
EPSS
Процентиль: 54%
0.00317
Низкий
7.5 High
CVSS3
Дефекты
CWE-798
CWE-287
Связанные уязвимости
CVSS3: 7.5
github
около 3 лет назад
Common encryption key appears to be used across all deployed instances of Serv-U FTP Server. Because of this an encrypted value that is exposed to an attacker can be simply recovered to plaintext.
EPSS
Процентиль: 54%
0.00317
Низкий
7.5 High
CVSS3
Дефекты
CWE-798
CWE-287