CVE-1999-1078: Weak Encryption
WSFTP Pro 6.0 uses weak encryption for passwords in its initialization files, which allows remote attackers to easily decrypt the passwords and gain privileges.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the WS_FTP Pro initialization files and the WS_FTP service: enforce strict filesystem permissions so only authorized administrators can read those files, and restrict network/management access to trusted IPs via firewall rules or ACLs.
- Operational
Remove any passwords stored in Ipswitch WS_FTP Pro 6.0 initialization files and rotate/change all credentials that were stored there or that may have been exposed.
Event History
Frequently Asked Questions
What is the severity of CVE-1999-1078?
CVE-1999-1078 is considered a high severity vulnerability due to weak encryption used for passwords.
How do I fix CVE-1999-1078?
To fix CVE-1999-1078, upgrade to a newer version of WS_FTP Pro that utilizes stronger encryption methods.
What are the potential impacts of CVE-1999-1078?
The potential impacts of CVE-1999-1078 include unauthorized access to sensitive information and elevated privileges for attackers.
Which version of WS_FTP Pro is affected by CVE-1999-1078?
WS_FTP Pro version 6.0 is specifically affected by CVE-1999-1078.
Can CVE-1999-1078 be exploited remotely?
Yes, CVE-1999-1078 can be exploited remotely due to weak password encryption in initialization files.