vendor:
FTP Serv-U
by:
SecurityFocus
7.5
CVSS
HIGH
Bypass Anti Brute-Force Function
287
CWE
Product Name: FTP Serv-U
Affected Version From: FTP Serv-U
Affected Version To: FTP Serv-U
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2002
FTP Serv-U Anti Brute-Force Bypass Vulnerability
FTP Serv-U is an internet FTP server from CatSoft. It contains an anti brute-force security feature which does not indicate whether an account is valid or not, after three unsuccessful login attempts a user is disconnected. Reconnection is not permitted until after a specified amount of time. It is possible for a remote user to bypass the anti brute-force function within FTP Serv-U. Once successfully logged into the server either anonymously or with a valid account, a user can from that point brute force other usernames and passwords without ever being disconnected. This could lead to a compromise of other user accounts on the ftp server.
Mitigation:
Ensure that the FTP server is configured to use strong passwords and that the anti-brute force feature is enabled.