PT-2014-2178 · Ipswitch · Ipswitch Whatsup Gold Tftp Server
Prabhu S Angadi
·
Published
2014-12-28
·
Updated
2017-08-29
·
CVE-2011-4722
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Ipswitch WhatsUp Gold TFTP Server version 1.0.0.24
Description
A directory traversal issue exists, allowing remote attackers to read arbitrary files by including a .. (dot dot) in the
Filename field of an RRQ operation.Recommendations
For Ipswitch WhatsUp Gold TFTP Server version 1.0.0.24, consider restricting access to the TFTP server until a patch is available. As a temporary workaround, avoid using the
Filename field with .. (dot dot) sequences in RRQ operations to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ipswitch Whatsup Gold Tftp Server