CVE-2001-1356: Critical severity Netwin SurgeFTP vulnerability
Published Aug 4, 2001
·Updated
NetWin SurgeFTP 2.0f and earlier encrypts passwords using weak hashing, a fixed salt value and modulo 40 calculations, which allows remote attackers to conduct brute force password guessing attacks against the administrator account on port 7021.
Affected Software
6 affected components
Netwin SurgeFTP=2.0a
Netwin SurgeFTP=2.0b
Netwin SurgeFTP=2.0c
Netwin SurgeFTP=2.0d
Netwin SurgeFTP=2.0e
Netwin SurgeFTP=2.0f
Event History
Aug 4, 2001
CVE Published
04:00 AM
Jun 11, 2002
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2001-1356?
CVE-2001-1356 is considered a medium severity vulnerability due to its potential for brute force password attacks.
2
How do I fix CVE-2001-1356?
To fix CVE-2001-1356, update to a later version of NetWin SurgeFTP that addresses the weak password hashing mechanism.
3
What software versions are affected by CVE-2001-1356?
CVE-2001-1356 affects NetWin SurgeFTP versions 2.0a through 2.0f.
4
What type of attack does CVE-2001-1356 allow?
CVE-2001-1356 allows remote attackers to conduct brute force password guessing attacks against the administrator account.
5
On which port does CVE-2001-1356 present a vulnerability?
CVE-2001-1356 presents a vulnerability on port 7021.