CVE-2004-1885: High severity Progress Ipswitch Ws Ftp Server vulnerability
Ipswitch WSFTP Server 4.0.2 allows remote authenticated users to execute arbitrary programs as SYSTEM by using the SITE command to modify certain iFtpSvc options that are handled by iftpmgr.exe.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-1885?
CVE-2004-1885 is considered to have a high severity due to its potential to allow remote authenticated users to execute arbitrary programs with SYSTEM privileges.
How do I fix CVE-2004-1885?
Fixing CVE-2004-1885 requires upgrading to a patched version of Ipswitch WS_FTP Server that addresses the vulnerability.
Who is affected by CVE-2004-1885?
CVE-2004-1885 affects users of Ipswitch WS_FTP Server version 4.0.2.
What type of attacks can be executed due to CVE-2004-1885?
CVE-2004-1885 allows attackers to execute arbitrary commands, potentially compromising the entire system.
Is there a workaround for CVE-2004-1885?
While the best solution is to update the software, restricting access to the SITE command can serve as a temporary workaround for CVE-2004-1885.