First published: Sat Aug 04 2001(Updated: )
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
NetWin SurgeFTP | =2.0c | |
NetWin SurgeFTP | =2.0a | |
NetWin SurgeFTP | =2.0d | |
NetWin SurgeFTP | =2.0e | |
NetWin SurgeFTP | =2.0f | |
NetWin SurgeFTP | =2.0b |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.