PT-2002-2802 · Ftgate · Ftgate+1
Published
2002-12-31
·
Updated
2008-09-05
·
CVE-2002-2082
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions:
FTGate and FTGate Pro version 1.05
Description:
The issue allows remote attackers to lock the mailboxes of other users before authentication succeeds, due to the premature locking of user mailboxes.
Recommendations:
For FTGate and FTGate Pro version 1.05, consider modifying the authentication process to lock user mailboxes only after successful authentication. As a temporary workaround, restrict access to the mailbox locking feature to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Ftgate
Ftgate Pro