Record summary

CVE-2015-1419 has a selected CVSS score of 5.0; EIP currently links 1 Nuclei template.

Description

Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.

Description source: CVE List

Exploitation context

Available material

Nuclei templates
1

Nuclei templates

1
ProjectDiscoveryMEDIUMvsftpd <= 3.0.2 - Access Restriction BypassCVSS 5

vsftpd 3.0.2 and earlier contain a vulnerability that allows remote attackers to bypass access restrictions due to improper parsing of the deny_file configuration directive.

Impact

Unauthenticated attackers can bypass access restrictions configured via the deny_file directive to access files that should be restricted, potentially exposing sensitive data on vsftpd servers.

Remediation

Update vsftpd to a version newer than 3.0.2 that properly parses and enforces the deny_file configuration directive to prevent access restriction bypass.

Authorspussycat0x
Template tagscvecve2015networkftpvsftpdtcppassivevuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:N/I:P/A:N
CPE: cpe:2.3:o:opensuse:opensuse:13.1:*:*:*:*:*:*:*
Shodan: vsFTPd

Source: ProjectDiscovery

References

4