CVE-2017-15272

MEDIUM

psftpd 10.0.4 Build 729 - Improper Authentication via Cleartext Password Storage

Title source: llm
STIX 2.1

Description

The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.

References (3)

Core 3
Core References
Third Party Advisory, VDB Entry mailing-list x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541518/100/0/threaded
Third Party Advisory x_refsource_misc
https://www.x41-dsec.de/lab/advisories/x41-2017-006-psftpd/

Scores

CVSS v3 5.3
EPSS 0.0056
EPSS Percentile 42.2%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-287 CWE-522
Status published
Products (1)
psftp/psftpd 10.0.4
Published Nov 15, 2017
Tracked Since Feb 18, 2026