CVE-2008-4677
autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating "I'm assuming that they're using the same id and password on that unchanged hostname, deliberately."
CVSS
- Versión: 2.0
- Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N
- Puntuación base: 4.3
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.95%
- Percentil entre todas las CVEs puntuadas: 80
- Fecha de la puntuación: 2/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-255
Referencias
- http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
- http://secunia.com/advisories/31464
- http://secunia.com/advisories/34418
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:236
- http://www.openwall.com/lists/oss-security/2008/10/06/4
- http://www.openwall.com/lists/oss-security/2008/10/16/2
- http://www.openwall.com/lists/oss-security/2008/10/20/2
- http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html
- http://www.securityfocus.com/archive/1/495432
- http://www.securityfocus.com/archive/1/495436
- http://www.securityfocus.com/bid/30670
- http://www.vupen.com/english/advisories/2008/2379
- https://bugzilla.redhat.com/show_bug.cgi?id=461750
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44419
- http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6
- http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html
- http://secunia.com/advisories/31464
- http://secunia.com/advisories/34418
- http://www.mandriva.com/security/advisories?name=MDVSA-2008:236
- http://www.openwall.com/lists/oss-security/2008/10/06/4
- http://www.openwall.com/lists/oss-security/2008/10/16/2
- http://www.openwall.com/lists/oss-security/2008/10/20/2
- http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html
- http://www.securityfocus.com/archive/1/495432
- http://www.securityfocus.com/archive/1/495436
- http://www.securityfocus.com/bid/30670
- http://www.vupen.com/english/advisories/2008/2379
- https://bugzilla.redhat.com/show_bug.cgi?id=461750
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44419
JSON original (NVD)
Mostrar
{
"id": "CVE-2008-4677",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.3,
"accessVector": "NETWORK",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "PARTIAL"
},
"acInsufInfo": false,
"impactScore": 2.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 8.6,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2008-10-22T18:00:00.910",
"references": [
{
"url": "http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6",
"source": "cve@mitre.org"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html",
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/31464",
"tags": [
"Vendor Advisory"
],
"source": "cve@mitre.org"
},
{
"url": "http://secunia.com/advisories/34418",
"source": "cve@mitre.org"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:236",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/06/4",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/16/2",
"source": "cve@mitre.org"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/20/2",
"source": "cve@mitre.org"
},
{
"url": "http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/495432",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/495436",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/30670",
"source": "cve@mitre.org"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2379",
"source": "cve@mitre.org"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=461750",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44419",
"source": "cve@mitre.org"
},
{
"url": "http://groups.google.com/group/vim_dev/browse_thread/thread/2f6fad581a037971/a5fcf4c4981d34e6?show_docid=a5fcf4c4981d34e6",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://lists.opensuse.org/opensuse-security-announce/2009-03/msg00004.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/31464",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://secunia.com/advisories/34418",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.mandriva.com/security/advisories?name=MDVSA-2008:236",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/06/4",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/16/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.openwall.com/lists/oss-security/2008/10/20/2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.rdancer.org/vulnerablevim-netrw-credentials-dis.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/495432",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/495436",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/bid/30670",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.vupen.com/english/advisories/2008/2379",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugzilla.redhat.com/show_bug.cgi?id=461750",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/44419",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-255"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "autoload/netrw.vim (aka the Netrw Plugin) 109, 131, and other versions before 133k for Vim 7.1.266, other 7.1 versions, and 7.2 stores credentials for an FTP session, and sends those credentials when attempting to establish subsequent FTP sessions to servers on different hosts, which allows remote FTP servers to obtain sensitive information in opportunistic circumstances by logging usernames and passwords. NOTE: the upstream vendor disputes a vector involving different ports on the same host, stating \"I'm assuming that they're using the same id and password on that unchanged hostname, deliberately.\""
},
{
"lang": "es",
"value": "autoload/netrw.vim (también conocido como Netrw Plugin) v109, v131, y versiones anteriores a v133k para Vim v7.1.266, otras versiones v7.1 , y v7.2, guardan las credenciales de las sesiones FTP y envían estos datos al intentar establecer sesiones FTP posteriores a los servidores en diferentes host, lo que permite a los servidores FTP obtener información sensible en circunstancias oportunas mediante la validación con nombres de usuario y contraseñas. NOTA: el fabricante cuestiona un vector involucrando a distintos puertos en un mismo host afirmando que \"Asumimos que están usando el mismo id y contraseña sobre el mismo servidor de manera intencionada\"."
}
],
"lastModified": "2026-06-16T22:58:17.630",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vim:vim:7.1:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "A8C5B265-A7DD-4D24-864C-BF1FEEF8F138"
},
{
"criteria": "cpe:2.3:a:vim:vim:7.1.266:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "99E9ABC5-442C-4693-8F86-A969AD89A0C1"
},
{
"criteria": "cpe:2.3:a:vim:vim:7.2:*:*:*:*:*:*:*",
"vulnerable": false,
"matchCriteriaId": "3613F5F4-9B8C-4020-8550-23310A41C85C"
}
],
"operator": "OR"
},
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:vim:netrw:109:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CD5B43D3-2813-4D24-A496-AEA00429117F"
},
{
"criteria": "cpe:2.3:a:vim:netrw:110:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "A2051781-F1FC-4D47-B047-439DF77679F7"
},
{
"criteria": "cpe:2.3:a:vim:netrw:111:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8DFB6EAD-0BEE-4FD3-823E-3B52D86603AE"
},
{
"criteria": "cpe:2.3:a:vim:netrw:112:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC46D98B-8655-4F84-A0C3-F29D989187D0"
},
{
"criteria": "cpe:2.3:a:vim:netrw:113:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "11E8CE7C-5483-48EC-9BFD-FDCEF4832E99"
},
{
"criteria": "cpe:2.3:a:vim:netrw:114:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "618E8E68-AF47-4EBD-A1CA-C310D4C36FCA"
},
{
"criteria": "cpe:2.3:a:vim:netrw:115:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "CC4D79BA-5C46-4E9C-9611-F4405D35C0FC"
},
{
"criteria": "cpe:2.3:a:vim:netrw:116:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6FEC552C-0A24-4A68-840A-301BA76B737A"
},
{
"criteria": "cpe:2.3:a:vim:netrw:118:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "FEC61FD6-ED14-443D-96CA-0879BB5413BB"
},
{
"criteria": "cpe:2.3:a:vim:netrw:120:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "8BF927C2-06B4-4123-87D5-41F08CA98AB0"
},
{
"criteria": "cpe:2.3:a:vim:netrw:121:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "778E1D0A-C2A7-43B7-B87E-05A1ADB8DDD9"
},
{
"criteria": "cpe:2.3:a:vim:netrw:122:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "B94004A1-17C4-48D4-9DA0-A6A1C8F37601"
},
{
"criteria": "cpe:2.3:a:vim:netrw:123:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "046706FD-9A64-4FCD-BC46-0C301BA9E5B2"
},
{
"criteria": "cpe:2.3:a:vim:netrw:128:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "6DE8FDD2-EB30-4B5D-BDDD-66338A6B816B"
},
{
"criteria": "cpe:2.3:a:vim:netrw:131:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "1910C099-42C8-45BD-B00E-FC2904E76423"
}
],
"operator": "OR"
}
],
"operator": "AND"
}
],
"vendorComments": [
{
"comment": "Not vulnerable. This issue did not affect the versions of vim as shipped with Red Hat Enterprise Linux 2.1, 3, 4, or 5.",
"lastModified": "2008-10-25T00:00:00",
"organization": "Red Hat"
}
],
"sourceIdentifier": "cve@mitre.org"
}