The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Netbox | S2sys | 2.5 (including) | 2.5 (including) |
Netbox | S2sys | 3.3 (including) | 3.3 (including) |
Netbox | S2sys | 4.0 (including) | 4.0 (including) |