CVE-2004-1884: High severity Ipswitch Ws Ftp Server vulnerability
Published Mar 23, 2004
·Updated
Ipswitch WSFTP Server 4.0.2 has a backdoor XXSESSMGRYY username with a default password, which allows remote attackers to gain access.
Affected Software
42 affected components
Ipswitch Ws Ftp Server=4.01
Ipswitch Ws Ftp Server=3.0_1
Ipswitch Ws Ftp Pro=6.0
Ipswitch Ws Ftp Pro=8.0_3
Ipswitch Ws Ftp Pro=7.5
Ipswitch Ws Ftp Pro=8.0_2
Progress Ipswitch Ws Ftp Server=1.0.1
Progress Ipswitch Ws Ftp Server=1.0.2
Progress Ipswitch Ws Ftp Server=1.0.3
Progress Ipswitch Ws Ftp Server=1.0.4
Progress Ipswitch Ws Ftp Server=1.0.5
Progress Ipswitch Ws Ftp Server=2.0
Progress Ipswitch Ws Ftp Server=2.0.1
Progress Ipswitch Ws Ftp Server=2.0.2
Progress Ipswitch Ws Ftp Server=2.0.3
Progress Ipswitch Ws Ftp Server=2.0.4
Progress Ipswitch Ws Ftp Server=3.0
Progress Ipswitch Ws Ftp Server=3.1
Progress Ipswitch Ws Ftp Server=3.1.1
Progress Ipswitch Ws Ftp Server=3.1.2
Progress Ipswitch Ws Ftp Server=3.1.3
Progress Ipswitch Ws Ftp Server=3.4
Progress Ipswitch Ws Ftp Server=4.0
Progress Ipswitch Ws Ftp Server=4.0.2
Progress Ws Ftp Server=1.0.1
Progress Ws Ftp Server=1.0.2
Progress Ws Ftp Server=1.0.3
Progress Ws Ftp Server=1.0.4
Progress Ws Ftp Server=1.0.5
Progress Ws Ftp Server=2.0
Progress Ws Ftp Server=2.0.1
Progress Ws Ftp Server=2.0.2
Progress Ws Ftp Server=2.0.3
Progress Ws Ftp Server=2.0.4
Progress Ws Ftp Server=3.0
Progress Ws Ftp Server=3.1
Progress Ws Ftp Server=3.1.1
Progress Ws Ftp Server=3.1.2
Progress Ws Ftp Server=3.1.3
Progress Ws Ftp Server=3.4
Progress Ws Ftp Server=4.0
Progress Ws Ftp Server=4.0.2
Remediation
Patch Available
Event History
Mar 23, 2004
CVE Published
05:00 AM
May 10, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2004-1884?
CVE-2004-1884 is considered a high severity vulnerability due to its backdoor access feature.
2
How do I fix CVE-2004-1884?
To fix CVE-2004-1884, change the default password for the XXSESS_MGRYY username and apply the latest security patches for the Ipswitch WS_FTP Server.
3
Which versions of Ipswitch WS_FTP are affected by CVE-2004-1884?
CVE-2004-1884 affects Ipswitch WS_FTP Server versions 4.0.2 and earlier, along with various WS_FTP Pro versions.
4
Can CVE-2004-1884 be exploited remotely?
Yes, CVE-2004-1884 can be exploited remotely by attackers to gain unauthorized access.
5
What does CVE-2004-1884 allow attackers to do?
CVE-2004-1884 allows attackers to gain remote access to systems using default credentials.