SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2009-3095

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as…

MEDIUM 5.0EPSS 12.6%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 12.6%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

The mod_proxy_ftp module in the Apache HTTP Server allows remote attackers to bypass intended access restrictions and send arbitrary commands to an FTP server via vectors related to the embedding of these commands in the Authorization HTTP header, as demonstrated by a certain module in VulnDisco Pack Professional 8.11.

CVSS 2.0
5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
EPSS
12.56% probability · 96th percentile
CISA KEV
Not listed
Affected
apache/http server · fedoraproject/fedora · debian/debian linux · opensuse/opensuse · suse/linux enterprise desktop · suse/linux enterprise server · apple/mac os x
Source
cve@mitre.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.