CVE-2002-2417
HIGH 10.0EPSS 4.2%
acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.
- CVSS v2.0
- 10.0 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 4.18% chance of exploitation in the next 30 days, 90th percentile
- Published
- 2007-11-01
- Updated
- 2024-08-08