First published: Wed Mar 10 2010(Updated: )
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Time Capsule | =7.5 | |
Apple AirPort Extreme | =7.5 | |
Apple AirPort Express | =7.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.