Vulnerability Name: | CCN-13726 |
Published: | 2003-11-11 |
Updated: | 2003-11-11 |
Summary: | The File Transfer (FTP) service enables access to a system using a weak authentication method with plaintext passwords. Additionally, programming flaws in this service may allow attackers to gain root access. Access should only be allowed from remote systems that require access. To verify that the configuration of TCP Wrappers is correct, use the tcpdchk and tcpdmatch utilities.
Because TCP Wrappers does not 'fail safe', it is advisable to put an 'ALL: ALL' entry in the /etc/hosts.deny file, and then explicitly allow required services in the /etc/hosts.allow file. |
CVSS v3 Severity: | |
CVSS v2 Severity: | |
Vulnerability Consequences: | Informational |
References: | Source: CCN Type: SANS Web site SANS Top 20 Internet Security Vulnerabilities Source: XF Type: UNKNOWN ftp-wrapper-allow(13726) |
Vulnerable Configuration: | Configuration CCN 1:![]() |
BACK |