CVE-2005-3296: Critical severity HPE HP-UX vulnerability
Published Oct 23, 2005
·Updated
The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.
Affected Software
6 affected components
HPE HP-UX=11.11
HPE HP-UX=11.00
HPE HP-UX=10.20
HPE HP-UX=10.20
HPE HP-UX=11.00
HPE HP-UX=11.11
Event History
Oct 23, 2005
CVE Published
via MITRE·08:00 AM
Data Sourced
via MITRE·08:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2005-3296?
CVE-2005-3296 is considered to be a critical vulnerability due to its ability to allow remote attackers to access sensitive directory listings.
2
How do I fix CVE-2005-3296?
To mitigate CVE-2005-3296, apply the latest patches released by HP for the affected versions of HP-UX.
3
Who is affected by CVE-2005-3296?
CVE-2005-3296 affects systems running HP-UX versions 10.20, 11.00, and 11.11.
4
What action can attackers perform using CVE-2005-3296?
Attackers can use the LIST command in the FTP server to list arbitrary directories as root without authentication.
5
When was CVE-2005-3296 disclosed?
CVE-2005-3296 was disclosed in October 2005.