CVE-2010-0962: Medium severity Apple Time Capsule vulnerability
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-0962?
CVE-2010-0962 has been classified as a high severity vulnerability due to its potential for remote exploitation.
How do I fix CVE-2010-0962?
To fix CVE-2010-0962, update the firmware of your Apple AirPort Express, AirPort Extreme, or Time Capsule to the latest version available.
What products are affected by CVE-2010-0962?
CVE-2010-0962 affects Apple AirPort Express, AirPort Extreme, and Time Capsule running firmware version 7.5.
What type of attack can exploit CVE-2010-0962?
CVE-2010-0962 can be exploited by remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding.
Is there a workaround for CVE-2010-0962?
Currently, the best workaround for CVE-2010-0962 is to disable FTP services if not needed until a firmware update is applied.