CVE Vulnerabilities

CVE-2010-0962

Published: Mar 10, 2010 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.

Affected Software

NameVendorStart VersionEnd Version
Airport_expressApple7.5 (including)7.5 (including)
Airport_extremeApple7.5 (including)7.5 (including)
Time_capsuleApple7.5 (including)7.5 (including)

References