CVE-2021-41637

HIGH

MELAG FTP Server 2.2.0.4 - Unauthenticated Sensitive Information Exposure via Incorrect Default Permissions

Title source: llm
STIX 2.1

Description

Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

References (1)

Core 1
Core References

Scores

CVSS v3 7.1
EPSS 0.0031
EPSS Percentile 22.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

Details

CWE
CWE-276
Status published
Products (1)
melag/ftp_server 2.2.0.4
Published Jun 24, 2022
Tracked Since Feb 18, 2026