The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.
References
Configurations
Configuration 1 (hide)
|
History
No history.
Information
Published : 2012-10-04 19:55
Updated : 2024-02-04 18:16
NVD link : CVE-2012-5301
Mitre link : CVE-2012-5301
CVE.ORG link : CVE-2012-5301
JSON object : View
Products Affected
cerberusftp
- ftp_server
CWE
CWE-310
Cryptographic Issues