CVE Vulnerabilities

CVE-2010-2620

Improper Authentication

Published: Jul 02, 2010 | Modified: Jul 06, 2010
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
9.3 HIGH
AV:N/AC:M/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Open&Compact FTP Server (Open-FTPD) 1.2 and earlier allows remote attackers to bypass authentication by sending (1) LIST, (2) RETR, (3) STOR, or other commands without performing the required login steps first.

Weakness

When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Affected Software

Name Vendor Start Version End Version
Open-ftpd Open-ftpd * 1.2 (including)
Open-ftpd Open-ftpd 1.0 (including) 1.0 (including)

Potential Mitigations

References