« Volver al listado

CVE-2008-5692

Estado: ModificadaMedia (5)—

Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-5692",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-12-19T18:30:00.407",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/wsftpweblog-adv.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://docs.ipswitch.com/WS_FTP_Server611/ReleaseNotes/index.htm?k_id=ipswitch_ftp_documents_worldwide_ws_ftpserverv611releasenotes#link12",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28822",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://securityreason.com/securityalert/4799",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487686/100/200/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487697/100/200/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27654",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0473",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/wsftpweblog-adv.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://docs.ipswitch.com/WS_FTP_Server611/ReleaseNotes/index.htm?k_id=ipswitch_ftp_documents_worldwide_ws_ftpserverv611releasenotes#link12",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28822",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://securityreason.com/securityalert/4799",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487686/100/200/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487697/100/200/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27654",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0473",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-287"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Ipswitch WS_FTP Server Manager before 6.1.1, and possibly other Ipswitch products, allows remote attackers to bypass authentication and read logs via a logLogout action to FTPLogServer/login.asp followed by a request to FTPLogServer/LogViewer.asp with the localhostnull account name."
    },
    {
      "lang": "es",
      "value": "Ipswitch WS_FTP Server Manager anterior a la version 6.1.1, y posiblemente otros productos de Ipswitch, permite a atacantes remotos eludir la autenticación y leer los logs a través de una acción logLogout a FTPLogServer/login.asp seguido por una solicitud de FTPLogServer/LogViewer.asp con el nombre de cuenta localhostnull."
    }
  ],
  "lastModified": "2026-06-16T23:00:48.990",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "898F836A-4413-4A14-9D99-E15CE2AF7660",
              "versionEndIncluding": "6.1"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:1.0.5:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "89C81A58-330F-41DC-BEF7-A5850D5DF0D1"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:2.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "69ADEDB9-99B5-4F1D-8D3F-CFAB6CA8DED2"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:2.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "BFBC2FE5-2367-4F08-B939-9F3F96356BC4"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:2.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "EE467C51-6B92-4291-BF49-14422E5FE719"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "40483FCD-0111-4950-8CAA-BE55DC3161D1"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.0.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "097E2EC7-83DB-47B1-BA69-0234FB2EC9B4"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.1.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "7F87D07A-769A-4D5F-8EAB-3A2FF877DD06"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.1.1:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "1329DB51-5871-4B3C-800D-EA0B99655862"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.1.2:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "440A634D-31F4-4B1A-8CAC-42368CBED0E8"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.1.3:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "C0B010EF-AA23-4297-B523-A6909E689D9A"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:3.14:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5ABD7295-9DB0-418E-ACCB-8623AA44AD39"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:4.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "155FCE9D-EA9C-48FF-9A07-49DD2232D2EB"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:4.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9EF2984F-1130-42A3-89F4-AB1CB1E5A4BF"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:4.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "81332CD2-A180-4D79-BA79-6B5FD560CC78"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.00:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "06DAC70D-AA7E-4F18-82CD-8EB93C64B1B0"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.01:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A37736C6-D729-41AC-BABD-2FBAC371E777"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.02:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "F6E87011-C9AA-4D52-A8F1-E3172B635929"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.03:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "4E2AB91D-0EFB-4E20-978D-D38168F4BFBD"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.04:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3EBA8A91-2C2D-4C50-AFD1-898C9C79C5F4"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:5.05:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "32212E07-9A0F-4E03-A83F-82D11BA0A256"
            },
            {
              "criteria": "cpe:2.3:a:ipswitch:ws_ftp:6.0:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "D0C1CC7B-B4F9-4F15-8EAC-033119C5DA37"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}