PT-2024-15794 · Unknown · Xlight Ftp Server

Fernando.Mengali

·

Published

2024-01-19

·

Updated

2024-05-17

·

CVE-2024-0737

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Xlightftpd Xlight FTP Server version 1.1
Description A problematic vulnerability was found in the Login component, where the manipulation of the user argument leads to denial of service. The attack can be initiated remotely.
Recommendations For Xlightftpd Xlight FTP Server version 1.1, consider restricting access to the Login component to minimize the risk of exploitation. As a temporary workaround, avoid using the user argument in the affected component until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Improper Resource Release

Weakness Enumeration

Related Identifiers

CVE-2024-0737

Affected Products

Xlight Ftp Server