Lucene search

K
nvd[email protected]NVD:CVE-2023-45198
HistoryOct 05, 2023 - 5:15 a.m.

CVE-2023-45198

2023-10-0505:15:42
web.nvd.nist.gov
cve-2023-45198
information leakage
ftpd
netbsd
mlsd
mlst
tnftpd vulnerability

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.2%

ftpd before “NetBSD-ftpd 20230930” can leak information about the host filesystem before authentication via an MLSD or MLST command. tnftpd (the portable version of NetBSD ftpd) before 20231001 is also vulnerable.

Affected configurations

NVD
Node
netbsdftpdRange<2023-09-30
OR
netbsdtnftpdRange<2023-10-01

7.5 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

0.001 Low

EPSS

Percentile

37.2%

Related for NVD:CVE-2023-45198