First published: Tue Dec 31 2002(Updated: )
The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Sharp Zaurus | =sl-5500 | |
Sharp Zaurus | =sl-5000d |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2002-1974 is classified as a high severity vulnerability due to the lack of authentication in the FTP service.
To mitigate CVE-2002-1974, enable authentication for the FTP service or disable FTP access entirely.
CVE-2002-1974 affects the Sharp Zaurus SL-5000D and SL-5500 PDAs.
Yes, CVE-2002-1974 can be exploited remotely as attackers can access the file system without authentication.
With CVE-2002-1974, attackers can gain root access to the file system and potentially modify or delete files.