CVE-2010-0962
Published Mar 10, 2010
Last updated 6 years ago
Overview
- Description
- The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5
- Impact score
- 2.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:N/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:h:apple:airport_express:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "4DD1D820-3B0F-4A29-9CBC-D2ADFFCC2D7E" }, { "criteria": "cpe:2.3:h:apple:airport_extreme:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E0F3C79E-CB98-4475-B506-1CC6F51EE407" }, { "criteria": "cpe:2.3:h:apple:time_capsule:7.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E5E48C63-EAB8-48D0-BF02-DFE311D9303C" } ], "operator": "OR" } ] } ]