NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Surgeftp | Netwin | 2.0a (including) | 2.0a (including) |
Surgeftp | Netwin | 2.0b (including) | 2.0b (including) |
Surgeftp | Netwin | 2.0c (including) | 2.0c (including) |
Surgeftp | Netwin | 2.0d (including) | 2.0d (including) |
Surgeftp | Netwin | 2.0e (including) | 2.0e (including) |
Surgeftp | Netwin | 2.0f (including) | 2.0f (including) |