VulnerabilityModified
CVE-2005-0798
Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.
HIGH 7.5EPSS 1.75%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.75%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Novell iChain Mini FTP Server 2.3, and possibly earlier versions, does not limit the number of incorrect logins, which makes it easier for remote attackers to conduct brute force login attacks.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 1.75% probability · 77th percentile
- CISA KEV
- Not listed
- Affected
- novell/ichain
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=111091517007681&w=2
- http://secunia.com/advisories/14607Vendor Advisory
- http://securitytracker.com/id?1013408
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htmVendor Advisory
- http://www.infobyte.com.ar/adv/ISR-05.htmlVendor Advisory
- http://www.osvdb.org/14648
- http://marc.info/?l=bugtraq&m=111091517007681&w=2
- http://secunia.com/advisories/14607Vendor Advisory
- http://securitytracker.com/id?1013408
- http://support.novell.com/cgi-bin/search/searchtid.cgi?/10096887.htmVendor Advisory
- http://www.infobyte.com.ar/adv/ISR-05.htmlVendor Advisory
- http://www.osvdb.org/14648
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.