« Volver al listado

CVE-2006-3222

Estado: ModificadaMedia (5)—

The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2006-3222",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:N/I:N/A:P",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "NONE"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2006-06-24T10:06:00.000",
  "references": [
    {
      "url": "http://attrition.org/pipermail/vim/2006-July/000921.html",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/20720",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-15.html",
      "tags": [
        "Patch"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.osvdb.org/26736",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/18570",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2467",
      "source": "cve@mitre.org"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27532",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://attrition.org/pipermail/vim/2006-July/000921.html",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/20720",
      "tags": [
        "Patch",
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.fortinet.com/FortiGuardCenter/advisory/FG-2006-15.html",
      "tags": [
        "Patch"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.osvdb.org/26736",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/18570",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2006/2467",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/27532",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-Other"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The FTP proxy module in Fortinet FortiOS (FortiGate) before 2.80 MR12 and 3.0 MR2 allows remote attackers to bypass anti-virus scanning via the Enhanced Passive (EPSV) FTP mode."
    },
    {
      "lang": "es",
      "value": "El módulo proxy FTP Fortinet FortiOS (FortiGate) anterior v2.80 MR12 y v3.0 MR2 permite a atacantes remotos superar el escaneo del anti-virus a través del modo Enhanced Passive (EPSV) FTP."
    }
  ],
  "lastModified": "2026-06-16T22:26:39.147",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.5_0mr4:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0779FEC-B7A9-416D-AC8B-A2F646C166F2"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.8_mr10:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "769D4FB0-780F-48B0-958B-8E088CD2CBF3"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.36:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A1A5E477-ADA7-469F-80EF-97EE2AF926B6"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.50:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BB2815EF-253B-4E3D-BFA7-265021783158"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.50_mr5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6810DDBF-3411-4FD9-981A-E8D5FA7FD0CF"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:2.80:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "767E66F6-7AF3-4541-8797-D7503D852044"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "631ED29C-890E-4C53-8ADB-0061125FEEDF"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:3.0_beta:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "973C42EB-2073-4ED9-AE15-F72C863394ED"
            },
            {
              "criteria": "cpe:2.3:o:fortinet:fortios:3.0_mr1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1A36F497-1BD7-466A-BA57-069BEA042EE0"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}