Lucene search

K
cve[email protected]CVE-2010-2968
HistoryOct 03, 2022 - 4:21 p.m.

CVE-2010-2968

2022-10-0316:21:08
CWE-264
web.nvd.nist.gov
21
cve-2010-2968
ftp daemon
wind river vxworks
remote attackers
brute-force attack

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.9%

The FTP daemon in Wind River VxWorks does not close the TCP connection after a number of failed login attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.

Affected configurations

NVD
Node
windrivervxworksRange6.8
OR
windrivervxworksMatch5
OR
windrivervxworksMatch5.5
OR
windrivervxworksMatch6
OR
windrivervxworksMatch6.4

7.8 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

COMPLETE

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:C/I:N/A:N

6.7 Medium

AI Score

Confidence

Low

0.004 Low

EPSS

Percentile

72.9%

Related for CVE-2010-2968