ID

VAR-200810-0529


TITLE

Hitachi JP1/File Transmission Server/FTP Denial of Service and Unauthorized Access Vulnerability

Trust: 0.6

sources: CNVD: CNVD-2008-5045

DESCRIPTION

JP1/File Transmission Server/FTP is an FTP-based file transfer server designed by Hitachi. There is a loophole in the implementation of JP1/File Transmission Server/FTP. If a remote attacker sends an FTP command with a special parameter to it, it will cause the connection to be reset or unauthorized to modify the file permissions on the server.

Trust: 0.6

sources: CNVD: CNVD-2008-5045

IOT TAXONOMY

category:['ICS', 'Network device']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2008-5045

AFFECTED PRODUCTS

vendor:nomodel: - scope: - version: -

Trust: 0.6

sources: CNVD: CNVD-2008-5045

CVSS

SEVERITY

CVSSV2

CVSSV3

CNVD: CNVD-2008-5045
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2008-5045
severity: MEDIUM
baseScore: 6.4
vectorString: AV:N/AC:L/AU:N/C:N/I:P/A:P
accessVector: NETWORK
accessComplexity: LOW
authentication: NONE
confidentialityImpact: NONE
integrityImpact: PARTIAL
availabilityImpact: PARTIAL
exploitabilityScore: 10.0
impactScore: 4.9
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

sources: CNVD: CNVD-2008-5045

PATCH

title:Patch for Hitachi JP1/File Transmission Server/FTP Denial of Service and Unauthorized Access Vulnerabilityurl:https://www.cnvd.org.cn/patchinfo/show/43048

Trust: 0.6

sources: CNVD: CNVD-2008-5045

EXTERNAL IDS

db:CNVDid:CNVD-2008-5045

Trust: 0.6

sources: CNVD: CNVD-2008-5045

SOURCES

db:CNVDid:CNVD-2008-5045

LAST UPDATE DATE

2022-05-04T09:35:56.452000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2008-5045date:2014-01-24T00:00:00

SOURCES RELEASE DATE

db:CNVDid:CNVD-2008-5045date:2008-10-17T00:00:00