CVE-2002-1209: Medium severity SolarWinds TFTP Server vulnerability
Directory traversal vulnerability in SolarWinds TFTP Server 5.0.55, and possibly earlier, allows remote attackers to read arbitrary files via "..\" (dot-dot backslash) sequences in a GET request.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2002-1209?
CVE-2002-1209 is classified as a medium severity vulnerability due to its potential for unauthorized file access.
How do I fix CVE-2002-1209?
To mitigate CVE-2002-1209, it is recommended to upgrade to the latest version of SolarWinds TFTP Server or apply any available patches.
What types of attacks can exploit CVE-2002-1209?
CVE-2002-1209 can be exploited by remote attackers using directory traversal techniques to access sensitive files on the server.
Which versions of SolarWinds TFTP Server are affected by CVE-2002-1209?
CVE-2002-1209 affects SolarWinds TFTP Server version 5.0.55 and possibly earlier versions.
What should I do if I cannot upgrade my SolarWinds TFTP Server due to legacy constraints related to CVE-2002-1209?
If upgrading is not possible, implement strict firewall rules and network segmentation to limit access to the TFTP server.