Lucene search

K
cve[email protected]CVE-2003-1596
HistoryOct 03, 2022 - 4:15 p.m.

CVE-2003-1596

2022-10-0316:15:43
CWE-264
web.nvd.nist.gov
23
cve-2003-1596
nwftpd.nlm
novell netware
ftp server
remote attackers
access restrictions
ftp session
security vulnerability

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.3%

NWFTPD.nlm before 5.03.12 in the FTP server in Novell NetWare does not properly restrict filesystem use by anonymous users with NFS Gateway home directories, which allows remote attackers to bypass intended access restrictions via an FTP session.

Affected configurations

NVD
Node
novellnetware_ftp_serverRange5.03b
OR
novellnetware_ftp_serverMatch5.01i
OR
novellnetware_ftp_serverMatch5.01o
OR
novellnetware_ftp_serverMatch5.01w
OR
novellnetware_ftp_serverMatch5.01y
OR
novellnetware_ftp_serverMatch5.02b
OR
novellnetware_ftp_serverMatch5.02i
OR
novellnetware_ftp_serverMatch5.02r
OR
novellnetware_ftp_serverMatch5.02y
AND
novellnetwareMatch5.1
OR
novellnetwareMatch6.0
OR
novellnetwareMatch6.5

7.5 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

69.3%

Related for CVE-2003-1596