Записи melag
6 опубликованных записей вендора melag.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 0
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-276 Incorrect Default Permissions2
- CWE-203 Observable Discrepancy1
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')1
- CWE-287 Improper Authentication1
- CWE-312 Cleartext Storage of Sensitive Information1
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
6 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
36Наблюдать | CVE-2021-41635Эксплойта нет | When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations omelag · ftp server · CWE-276 | Высокая8,8 | — | 2,1 % | 24 июн. 2022 г. |
31Наблюдать | CVE-2021-41638Эксплойта нет | The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files onmelag · ftp server · CWE-287 | Высокая7,5 | — | 1,7 % | 24 июн. 2022 г. |
28Наблюдать | CVE-2021-41637Эксплойта нет | Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which inclumelag · ftp server · CWE-276 | Высокая7,1 | — | 0,3 % | 24 июн. 2022 г. |
26Наблюдать | CVE-2021-41636Эксплойта нет | MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire melag · ftp server · CWE-22 | Средняя6,5 | — | 1,5 % | 24 июн. 2022 г. |
22Наблюдать | CVE-2021-41639Эксплойта нет | MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.melag · ftp server · CWE-312 | Средняя5,5 | — | 0,2 % | 24 июн. 2022 г. |
21Наблюдать | CVE-2021-41634Эксплойта нет | A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.melag · ftp server · CWE-203 | Средняя5,3 | — | 1,0 % | 24 июн. 2022 г. |
- CVE-2021-4163536Наблюдать
When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations o
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %melag · ftp server24 июн. 2022 г.
- CVE-2021-4163831Наблюдать
The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files on
ВысокаяCVSS 7,5Эксплойта нетEPSS 2 %melag · ftp server24 июн. 2022 г.
- CVE-2021-4163728Наблюдать
Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which inclu
ВысокаяCVSS 7,1Эксплойта нетEPSS 0 %melag · ftp server24 июн. 2022 г.
- CVE-2021-4163626Наблюдать
MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire
СредняяCVSS 6,5Эксплойта нетEPSS 1 %melag · ftp server24 июн. 2022 г.
- CVE-2021-4163922Наблюдать
MELAG FTP Server 2.2.0.4 stores unencrpyted passwords of FTP users in a local configuration file.
СредняяCVSS 5,5Эксплойта нетEPSS 0 %melag · ftp server24 июн. 2022 г.
- CVE-2021-4163421Наблюдать
A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.
СредняяCVSS 5,3Эксплойта нетEPSS 1 %melag · ftp server24 июн. 2022 г.