PT-2001-1962 · Cisco · Cisco Tftp Server

Published

2001-10-12

·

Updated

2017-12-19

·

CVE-2001-0783

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Cisco TFTP server version 1.1
Description The issue allows remote attackers to read arbitrary files via a ..(dot dot) attack in the GET command. This is a significant security concern as it potentially exposes sensitive information.
Recommendations For Cisco TFTP server version 1.1, consider restricting access to the TFTP server until a patch is available. As a temporary workaround, limit the files and directories that can be accessed through the TFTP server to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2001-0783

Affected Products

Cisco Tftp Server