Lucene search

K
cve[email protected]CVE-2008-0604
HistoryOct 03, 2022 - 4:14 p.m.

CVE-2008-0604

2022-10-0316:14:09
CWE-255
web.nvd.nist.gov
12
xlight ftp server
ldap authentication
bypass
remote attackers
nvd
cve-2008-0604

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.1%

The LDAP authentication feature in XLight FTP Server before 2.83, when used with some unspecified LDAP servers, does not check for blank passwords, which allows remote attackers to bypass intended access restrictions.

Affected configurations

NVD
Node
xlight_ftp_serverxlight_ftp_serverRange2.82

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

7 High

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.1%

Related for CVE-2008-0604