← Back to CVEs
CVE-2020-8634
HIGH7.8
Description
Wing FTP Server v6.2.3 for Linux, macOS, and Solaris sets insecure permissions on files modified within the HTTP file management interface, resulting in files being saved with world-readable and world-writable permissions. If a sensitive system file were edited this way, a low-privilege user may escalate privileges to root.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/7/2020
Last Modified11/21/2024
Sourcenvd
Honeypot Sightings0
Affected Products
wftpserver:wing_ftp_server
Weaknesses (CWE)
CWE-281
References
https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php(cve@mitre.org)
https://www.hooperlabs.xyz/disclosures/cve-2020-8635.php(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.