CVE Vulnerabilities

CVE-2001-1356

Published: Aug 04, 2001 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.

Affected Software

Name Vendor Start Version End Version
Surgeftp Netwin 2.0a 2.0a
Surgeftp Netwin 2.0b 2.0b
Surgeftp Netwin 2.0c 2.0c
Surgeftp Netwin 2.0d 2.0d
Surgeftp Netwin 2.0e 2.0e
Surgeftp Netwin 2.0f 2.0f

References