PT-2024-12771 · Unknown · Raidenftpd
Published
2024-02-13
·
Updated
2024-10-21
·
CVE-2023-38960
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
RaidenFTPD version 2.4 build 4005
Description
The issue allows a local attacker to gain privileges and execute arbitrary code via a crafted executable running from the installation directory. This is due to an Insecure Permissions problem in the software.
Recommendations
For version 2.4 build 4005, consider restricting access to the installation directory to prevent local attackers from executing arbitrary code until a patch is available. As a temporary workaround, ensure that only trusted executables are run from the installation directory.
Exploit
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Raidenftpd