First published: Mon Apr 05 2010(Updated: )
NWFTPD.nlm in the FTP server in Novell NetWare 6.0 before SP4 and 6.5 before SP1 does not enforce domain-name login restrictions, which allows remote attackers to bypass intended access control via an FTP connection.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Novell Netware Ftp Server | ||
Novell NetWare | =6.0 | |
Novell NetWare | =6.0-sp1 | |
Novell NetWare | =6.0-sp2 | |
Novell NetWare | =6.0-sp3 | |
Novell NetWare | =6.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2003-1593 is classified as a moderate risk vulnerability.
To fix CVE-2003-1593, update Novell NetWare to version 6.0 SP4 or 6.5 SP1 or later.
CVE-2003-1593 affects Novell NetWare 6.0 before SP4 and 6.5 before SP1.
An attacker can bypass intended access control via an FTP connection due to the lack of domain-name login restrictions.
Yes, the vulnerability allows remote attackers to bypass authentication mechanisms.