CVE-2010-0962

Apple AirPort Express/AirPort Extreme/Time Capsule <7.5 - RCE

Title source: llm
STIX 2.1

Description

The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.

References (5)

Core 5
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/56701
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509867/100/0/threaded
Exploit vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/38543
Mailing List mailing-list x_refsource_fulldisc
http://seclists.org/fulldisclosure/2010/Mar/106
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/509974/100/0/threaded

Scores

EPSS 0.0125
EPSS Percentile 66.2%

Details

CWE
CWE-264
Status published
Products (3)
apple/airport_express 7.5
apple/airport_extreme 7.5
apple/time_capsule 7.5
Published Mar 10, 2010
Tracked Since Feb 18, 2026