« Volver al listado

CVE-2004-2532

Estado: ModificadaAlta (10)—

Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2004-2532",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": false,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2004-12-31T05:00:00.000",
  "references": [
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0216.html",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/8877",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/10886",
      "tags": [
        "Exploit"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16925",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://archives.neohapsis.com/archives/fulldisclosure/2004-08/0216.html",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/8877",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/10886",
      "tags": [
        "Exploit"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/16925",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-255"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as that new user, and then using the SITE EXEC command."
    }
  ],
  "lastModified": "2026-06-16T22:09:49.803",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BBE64EE8-9FCE-43EF-8DE3-0BC90DE982D3",
              "versionEndIncluding": "5.0.0.11"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.16:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0CB703F7-4806-4E3F-850E-ACC127892899"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:3.0.0.17:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D6E3F784-86CB-46FC-97FB-1F43F140C9ED"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:3.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "022E0AF9-48FA-41C4-A109-4A3284A721BE"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:3.1.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "397E88A4-9E82-4818-B176-1C049993F1C4"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:3.1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D7DD649F-E290-4E8E-B61F-3950A2157938"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:4.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "51BE6EDE-C7BC-4730-9602-160A027D8F25"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:4.1.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7DE0A612-CF94-4DBE-808C-AE4CA9DD2C3B"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:4.1.0.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F20066E0-BAE8-462F-86B5-A39DDB5D11C4"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:5.0.0.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "78B460EA-F742-4524-B213-BF92ABF82ABC"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:5.0.0.4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6E646B1A-167C-4DB6-84C1-77B071AC605A"
            },
            {
              "criteria": "cpe:2.3:a:solarwinds:serv-u_file_server:5.0.0.9:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EF068DF2-7298-4648-BA80-06321599E723"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}