PT-2024-12771 · Unknown · Raidenftpd

Published

2024-02-13

·

Updated

2024-10-21

·

CVE-2023-38960

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions RaidenFTPD version 2.4 build 4005
Description The issue allows a local attacker to gain privileges and execute arbitrary code via a crafted executable running from the installation directory. This is due to an Insecure Permissions problem in the software.
Recommendations For version 2.4 build 4005, consider restricting access to the installation directory to prevent local attackers from executing arbitrary code until a patch is available. As a temporary workaround, ensure that only trusted executables are run from the installation directory.

Exploit

Fix

Incorrect Default Permissions

Weakness Enumeration

Related Identifiers

CVE-2023-38960

Affected Products

Raidenftpd