CVE-2006-1951: Medium severity SolarWinds TFTP Server vulnerability
Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2006-1951?
CVE-2006-1951 is classified as a medium severity vulnerability due to its potential for exposing sensitive files through directory traversal.
How do I fix CVE-2006-1951?
To fix CVE-2006-1951, upgrade SolarWinds TFTP Server to version 8.2 or later, as this version addresses the directory traversal vulnerability.
What versions of SolarWinds TFTP Server are affected by CVE-2006-1951?
CVE-2006-1951 affects SolarWinds TFTP Server version 8.1 and earlier, as well as versions 5.0.60 standard and 5.0.55 standard.
What types of attacks can exploit CVE-2006-1951?
CVE-2006-1951 can be exploited by remote attackers who send crafted GET requests to download arbitrary files from the server.
Is CVE-2006-1951 still a risk today?
While the immediate threat of CVE-2006-1951 is lower for current systems, any outdated software still running vulnerable versions poses a risk.