SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2016-9499

An attacker may use this information to determine valid user accounts and enumerate them.

MEDIUM 5.3EPSS 7.77%

Does this matter?

Lower severity and a low EPSS score (7.77%). Track it; it rarely justifies an emergency change on its own.

Description

Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.

CVSS 3.0
5.3 MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
EPSS
7.77% probability · 94th percentile
CISA KEV
Not listed
Weakness
CWE-204, CWE-200
Affected
accellion/ftp server
Source
cret@cert.org

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.