CVE-2001-1356
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.82%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
- CVSS 2.0
- 10.0 HIGHAV:N/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 3.82% probability · 89th percentile
- CISA KEV
- Not listed
- Affected
- netwin/surgeftp
- Source
- cve@mitre.org
References
- http://online.securityfocus.com/archive/1/201951Vendor Advisory
- http://www.iss.net/security_center/static/6961.phpVendor Advisory
- http://www.securityfocus.com/bid/3157Vendor Advisory
- http://online.securityfocus.com/archive/1/201951Vendor Advisory
- http://www.iss.net/security_center/static/6961.phpVendor Advisory
- http://www.securityfocus.com/bid/3157Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.