CVE-2024-48651

Published Nov 29, 2024

Last updated 3 months ago

Overview

Description
In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql.
Source
cve@mitre.org
NVD status
Awaiting Analysis

Risk scores

CVSS 3.1

Type
Secondary
Base score
7.5
Impact score
3.6
Exploitability score
3.9
Vector string
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity
HIGH

Social media

Hype score
Not currently trending
  1. CVE-2024-48651: Vulnerability in ProFTPD Server, 7.5 rating❗️ A bug discovered a few days ago allows attackers to gain root level access on vulnerable systems. Search at https://t.co/hv7QKSr5Jp: 👉 Link: https://t.co/t823kq3wRG #cybersecurity #vulnerability_map #proftpd https:

    @Netlas_io

    5 Dec 2024

    630 Impressions

    4 Retweets

    10 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  2. Warning: High-severity vulnerability in #ProFTPD. #CVE-2024-48651 CVSS: 7.5. An attacker can gain unintended access privileges by exploiting this misconfiguration. More info: https://t.co/qsU5qBfIqQ. #Patch #Patch #Patch

    @CCBalert

    4 Dec 2024

    22 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  3. ⚠️⚠️ CVE-2024-48651: ProFTPD Vulnerability Grants Root Access to Attackers 🎯2.4m+ Results are found on the https://t.co/pb16tGYaKe nearly year. 🔗FOFA Link:https://t.co/v9nRq2h5DV FOFA Query:app="ProFTPD" 🔖Refer: https://t.co/3doNvWZstx #OSINT #FOFA #CyberSecurity… https:/

    @fofabot

    4 Dec 2024

    856 Impressions

    6 Retweets

    6 Likes

    5 Bookmarks

    0 Replies

    0 Quotes

  4. 🚨Alert🚨CVE-2024-48651: ProFTPD Vulnerability Grants Root Access to Attackers 📊 673K+ Services are found on the https://t.co/ysWb28BTvF yearly. 🔗Hunter Link: https://t.co/QjReTDAkab 👇Query HUNTER:/product.name="ProFTPD" SHODAN: product:"ProFTPD" FOFA: app="ProFTPD" 📰Refer:…

    @HunterMapping

    4 Dec 2024

    1358 Impressions

    7 Retweets

    17 Likes

    7 Bookmarks

    0 Replies

    0 Quotes

  5. CVE-2024-48651 (CVSS:7.5, HIGH) is Awaiting Analysis. In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of th..https://t.co/TqJz7ZeR45 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    @cracbot

    4 Dec 2024

    5 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  6. 🚨🚨CVE-2024-48651(CVSS: 7.5): ProFTPD Vulnerability Grants Root Access to Attackers ⚠Popular FTP server ProFTPD has been found to contain a critical security flaw that could allow attackers to gain root access to vulnerable systems. ZoomEye Dork👉app="ProFTPD" 7.05M+ results… h

    @zoomeye_team

    3 Dec 2024

    568 Impressions

    2 Retweets

    8 Likes

    3 Bookmarks

    0 Replies

    0 Quotes

  7. ProFTPD Vulnerability Grants Root Access to Attackers #ProFTPD users beware! Discover the details of CVE-2024-48651, a critical vulnerability that allows attackers to gain root access. https://t.co/6lN4d4CMPw

    @the_yellow_fall

    3 Dec 2024

    1001 Impressions

    9 Retweets

    24 Likes

    4 Bookmarks

    0 Replies

    0 Quotes

  8. The severity is increased for this new vulnerability affecting ProFTPD (CVE-2024-48651) https://t.co/im0Ol0sbEc

    @vuldb

    29 Nov 2024

    8 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  9. CVE-2024-48651 Unauthorized Root Access via Group Inheritance Flaw in ProFTPD 1.3.8b In ProFTPD up to version 1.3.8b before update cec01cc, there is an issue with supplemental group inheritance. This issue gives ... https://t.co/L5wpgpfPvN

    @VulmonFeeds

    29 Nov 2024

    57 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes

  10. CVE-2024-48651 In ProFTPD through 1.3.8b before cec01cc, supplemental group inheritance grants unintended access to GID 0 because of the lack of supplemental groups from mod_sql. https://t.co/wFB0dZQRqC

    @CVEnew

    29 Nov 2024

    444 Impressions

    0 Retweets

    0 Likes

    0 Bookmarks

    0 Replies

    0 Quotes