SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2015-7665

Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which allows remote FTP servers to discover the Tor client IP address by reading a (1) PORT or (2) EPRT command.

MEDIUM 5.3EPSS 1.60%

Does this matter?

Lower severity and a low EPSS score (1.60%). Track it; it rarely justifies an emergency change on its own.

Description

Tails before 1.7 includes the wget program but does not prevent automatic fallback from passive FTP to active FTP, which allows remote FTP servers to discover the Tor client IP address by reading a (1) PORT or (2) EPRT command. NOTE: within wget itself, the automatic fallback is not considered a vulnerability by CVE.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
1.60% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-200
Affected
tails project/tails
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.