First published: Tue Dec 31 2002(Updated: )
Iomega Network Attached Storage (NAS) A300U, and possibly other models, does not allow the FTP service to be disabled, which allows local users to access home directories via FTP even when access to all shared directories have been disabled.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Iomega NAS | =a300u |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1863 is classified as a moderate severity vulnerability due to its potential for unauthorized access to sensitive data.
To mitigate CVE-2002-1863, ensure that access to FTP services is restricted and implement network segmentation.
CVE-2002-1863 affects Iomega Network Attached Storage A300U and possibly other models that do not allow FTP service to be disabled.
The consequences of CVE-2002-1863 include unauthorized local access to home directories even when shared directory access is disabled.
There are no current reports indicating that CVE-2002-1863 is actively being exploited in the wild, but it remains a potential security risk.