CVE-2010-2467: Medium severity lenels2 netbox vulnerability
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2010-2467?
CVE-2010-2467 has a medium severity rating due to the lack of an FTP password that allows unauthorized access to sensitive backup files.
How do I fix CVE-2010-2467?
To fix CVE-2010-2467, ensure that a password is set for the FTP server used for database backups.
Which software versions are affected by CVE-2010-2467?
CVE-2010-2467 affects S2 Security NetBox versions 2.5, 3.3, and 4.0, as well as Linear eMerge 50 and 5000 and Sonitrol eAccess.
Who is likely to exploit CVE-2010-2467?
Attackers with network access may exploit CVE-2010-2467 to download sensitive database backup files via the unsecured FTP access.
Is there a patch available for CVE-2010-2467?
As of now, there is no specific patch detailed for CVE-2010-2467, but configuring FTP access securely is essential.