CVE-2017-15272
MEDIUMpsftpd 10.0.4 Build 729 - Improper Authentication via Cleartext Password Storage
Title source: llmDescription
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.
References (3)
Core 3
Core References
Third Party Advisory, VDB Entry x_refsource_misc
http://packetstormsecurity.com/files/144972/PSFTPd-Windows-FTP-Server-10.0.4-Build-729-Use-After-Free-Log-Injection.html
Third Party Advisory, VDB Entry mailing-list
x_refsource_bugtraq
http://www.securityfocus.com/archive/1/541518/100/0/threaded
Third Party Advisory x_refsource_misc
https://www.x41-dsec.de/lab/advisories/x41-2017-006-psftpd/
Scores
CVSS v3
5.3
EPSS
0.0056
EPSS Percentile
42.2%
Attack Vector
LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Details
CWE
CWE-287
CWE-522
Status
published
Products (1)
psftp/psftpd
10.0.4
Published
Nov 15, 2017
Tracked Since
Feb 18, 2026