The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.
References
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 01:44
Type | Values Removed | Values Added |
---|---|---|
References | () http://www.cerberusftp.com/products/releasenotes.html - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/79503 - |
Information
Published : 2012-10-04 19:55
Updated : 2024-11-21 01:44
NVD link : CVE-2012-5301
Mitre link : CVE-2012-5301
CVE.ORG link : CVE-2012-5301
JSON object : View
Products Affected
cerberusftp
- ftp_server
CWE
CWE-310
Cryptographic Issues