« Volver al listado

CVE-2007-6741

Estado: ModificadaMedia (6.5)—

The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as demonstrated by an FTP bounce attack against a NAT server, a related issue to CVE-1999-0017.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-6741",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 6.5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:S/C:P/I:P/A:P",
          "authentication": "SINGLE",
          "integrityImpact": "PARTIAL",
          "accessComplexity": "LOW",
          "availabilityImpact": "PARTIAL",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 6.4,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 8,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2010-10-19T20:00:02.580",
  "references": [
    {
      "url": "http://code.google.com/p/pyftpdlib/issues/detail?id=11",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/detail?r=32",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/diff?spec=svn32&r=32&format=side&path=/trunk/pyftpdlib/FTPServer.py",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/issues/detail?id=11",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/browse/trunk/HISTORY",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/detail?r=32",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://code.google.com/p/pyftpdlib/source/diff?spec=svn32&r=32&format=side&path=/trunk/pyftpdlib/FTPServer.py",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-264"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "The ftp_PORT function in FTPServer.py in pyftpdlib before 0.2.0 does not prevent TCP connections to privileged ports if the destination IP address matches the source IP address of the connection from the FTP client, which might allow remote authenticated users to conduct FTP bounce attacks via crafted FTP data, as demonstrated by an FTP bounce attack against a NAT server, a related issue to CVE-1999-0017."
    },
    {
      "lang": "es",
      "value": "La función ftp_PORT en FTPSErver.py en pyftpdlib anterior a v0.2.0 no previene conexiones TCP de puertos privilegiados si la dirección IP de destino compara el código de la dirección IP de origen de clientes FTP, que debería permitir autenticación de usuarios remotos dirigir un ataque \"FTP bounce\" a través de datos FTP manipulados, como quedó demotrado en el ataque \"FTP bound\" contra el servidor NAT, tema relacionado con CVE-1999-0017."
    }
  ],
  "lastModified": "2026-06-16T22:48:41.037",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:g.rodola:pyftpdlib:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "807615BB-C28B-462D-B0C7-4950E31B0CC6",
              "versionEndIncluding": "0.1.1"
            },
            {
              "criteria": "cpe:2.3:a:g.rodola:pyftpdlib:0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DB3D49FE-C51B-49E8-895E-AD4C4E138425"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}