PT-2022-8164 · Enterprisedb · Enterprisedt Completeftp

Be0Vlk

+1

·

Published

2022-02-14

·

Updated

2022-02-23

·

CVE-2019-16864

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions EnterpriseDT CompleteFTP versions prior to 12.1.4
Description The issue allows for Remote Code Execution by leveraging a Windows user account that has SSH access. The exec command is always run as SYSTEM.
Recommendations For versions prior to 12.1.4, update to version 12.1.4 or later to resolve the issue. As a temporary workaround, consider restricting SSH access to trusted users only until a patch is applied.

Exploit

Fix

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2019-16864

Affected Products

Enterprisedt Completeftp