PoC Index

CVE-2021-41637

HIGH 7.1EPSS 0.3%

Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

CVSS v3.1
7.1 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
CVSS v2.0
3.6 LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
EPSS
0.32% chance of exploitation in the next 30 days, 25th percentile
Published
2022-06-24
Updated
2024-08-04

Proof-of-concept exploits (1)

References

Related