CVE-2000-0015: Medium severity Ascend Cascadeview Ux vulnerability
CascadeView TFTP server allows local users to gain privileges via a symlink attack.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Remove
Remove
CascadeView TFTP serverfrom your environment.Uninstall the CascadeView TFTP server component if it is not required.
- Configuration
Disable the CascadeView TFTP server to prevent local users from exploiting a symlink attack to gain privileges.
Ascend Cascadeview Ux (CascadeView TFTP server) tftp_enabled = false - Compensating control
Prevent local users from creating or modifying files in the TFTP server directories (remove write permissions for non-administrative accounts); run the TFTP service with least privilege (unprivileged user and/or chroot) and restrict who can access the host locally to mitigate symlink-based privilege escalation.
Event History
Frequently Asked Questions
What is the severity of CVE-2000-0015?
CVE-2000-0015 is considered a high severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2000-0015?
To fix CVE-2000-0015, ensure that the TFTP server is configured to prevent symlink attacks and restrict local user privileges.
Who is affected by CVE-2000-0015?
Users of Ascend CascadeView UX version 1.0 are affected by CVE-2000-0015.
What type of attack does CVE-2000-0015 involve?
CVE-2000-0015 involves a symlink attack that allows local users to gain elevated privileges.
When was CVE-2000-0015 published?
CVE-2000-0015 was published in January 2000.