CVE-2020-5196
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.
Cerberus FTP Server Enterprise Edition versiones anteriores a 11.0.3 y 10.0.18, permite a un atacante autenticado crear archivos, mostrar archivos ocultos, enumerar directorios y listar archivos sin el permiso para comprimir y descargar (o descomprimir y cargar) archivos. Existen varias maneras de omitir determinados permisos utilizando las funcionalidades de descompresión y descompresión. Como resultado, los usuarios sin permiso pueden visualizar archivos, carpetas y archivos ocultos, y pueden crear directorios sin permiso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-02 CVE Reserved
- 2020-01-14 CVE Published
- 2023-03-08 EPSS Updated
- 2024-08-04 CVE Updated
- 2024-08-04 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-276: Incorrect Default Permissions
CAPEC
References (3)
URL | Tag | Source |
---|
URL | Date | SRC |
---|---|---|
https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilities | 2024-08-04 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cerberusftp Search vendor "Cerberusftp" | Ftp Server Search vendor "Cerberusftp" for product "Ftp Server" | >= 10.0.0 < 10.0.18 Search vendor "Cerberusftp" for product "Ftp Server" and version " >= 10.0.0 < 10.0.18" | enterprise |
Affected
| ||||||
Cerberusftp Search vendor "Cerberusftp" | Ftp Server Search vendor "Cerberusftp" for product "Ftp Server" | >= 11.0.0 < 11.0.3 Search vendor "Cerberusftp" for product "Ftp Server" and version " >= 11.0.0 < 11.0.3" | enterprise |
Affected
|