ID |
CVE-2019-7227
|
Sažetak |
In the ABB IDAL FTP server, an authenticated attacker can traverse to arbitrary directories on the hard disk with "CWD ../" and then use the FTP server functionality to download and upload files. An unauthenticated attacker can take advantage of the hardcoded or default credential pair exor/exor to become an authenticated attacker. |
Reference |
|
CVSS |
Base: | 4.1 |
Impact: | 4.9 |
Exploitability: | 5.1 |
|
Pristup |
Vektor | Složenost | Autentikacija |
ADJACENT_NETWORK |
LOW |
SINGLE |
|
Impact |
Povjerljivost | Cjelovitost | Dostupnost |
PARTIAL |
PARTIAL |
NONE |
|
CVSS vektor |
AV:A/AC:L/Au:S/C:P/I:P/A:N |
Zadnje važnije ažuriranje |
30-11-2022 - 21:41 |
Objavljeno |
27-06-2019 - 16:15 |