PT-2022-11447 · Melag · Melag Ftp Server
Carsten Sandker
+1
·
Published
2022-06-24
·
Updated
2022-07-01
·
CVE-2021-41637
CVSS v3.1
7.1
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
MELAG FTP Server version 2.2.0.4
Description
The issue concerns weak access control permissions that allow the "Everyone" group to read the local FTP configuration file. This file contains unencrypted passwords of all FTP users, among other information.
Recommendations
For MELAG FTP Server version 2.2.0.4, consider restricting access to the local FTP configuration file to prevent unauthorized reading of sensitive information, including unencrypted passwords, until a patch or fix is available. As a temporary workaround, restrict the "Everyone" group's permissions to minimize the risk of exploitation.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Melag Ftp Server