PT-2002-2802 · Ftgate · Ftgate+1

Published

2002-12-31

·

Updated

2008-09-05

·

CVE-2002-2082

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions: FTGate and FTGate Pro version 1.05
Description: The issue allows remote attackers to lock the mailboxes of other users before authentication succeeds, due to the premature locking of user mailboxes.
Recommendations: For FTGate and FTGate Pro version 1.05, consider modifying the authentication process to lock user mailboxes only after successful authentication. As a temporary workaround, restrict access to the mailbox locking feature to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-2082

Affected Products

Ftgate
Ftgate Pro