{"api_version":"1","generated_at":"2026-07-23T07:03:21+00:00","cve":"CVE-2002-2417","urls":{"html":"https://cve.report/CVE-2002-2417","api":"https://cve.report/api/cve/CVE-2002-2417.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2002-2417","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2002-2417"},"summary":{"title":"CVE-2002-2417","description":"acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.","state":"PUBLISHED","assigner":"mitre","published_at":"2002-12-31 05:00:00","updated_at":"2025-04-03 01:03:51"},"problem_types":["CWE-287","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"10","severity":"","vector":"AV:N/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.iss.net/security_center/static/10681.php","name":"http://www.iss.net/security_center/static/10681.php","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ISS X-Force Database: acftp-authentication-bypass (10681): acFTP could allow an attacker to bypass authentication","mime":"text/html","httpstatus":"-1","archivestatus":"200"},{"url":"http://www.securityfocus.com/archive/1/300929","name":"http://www.securityfocus.com/archive/1/300929","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"SecurityFocus","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://securityreason.com/securityalert/3334","name":"http://securityreason.com/securityalert/3334","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"acFTP Authentication Issue - CXSecurity.com","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0088.html","name":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0088.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"404"},{"url":"http://www.securityfocus.com/bid/6235","name":"http://www.securityfocus.com/bid/6235","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"acFTP Invalid Password Weak Authentication Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2002-2417","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2002-2417","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2002","cve_id":"2417","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"acftp","cpe5":"acftp","cpe6":"1.4","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-08T04:06:53.859Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"6235","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/6235"},{"name":"3334","tags":["third-party-advisory","x_refsource_SREASON","x_transferred"],"url":"http://securityreason.com/securityalert/3334"},{"name":"acftp-authentication-bypass(10681)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"http://www.iss.net/security_center/static/10681.php"},{"name":"20021123 acFTP Authentication Issue","tags":["mailing-list","x_refsource_VULNWATCH","x_transferred"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0088.html"},{"name":"20021124 acFTP Authentication Issue","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/300929"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2002-11-23T00:00:00.000Z","descriptions":[{"lang":"en","value":"acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2007-11-28T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"6235","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/6235"},{"name":"3334","tags":["third-party-advisory","x_refsource_SREASON"],"url":"http://securityreason.com/securityalert/3334"},{"name":"acftp-authentication-bypass(10681)","tags":["vdb-entry","x_refsource_XF"],"url":"http://www.iss.net/security_center/static/10681.php"},{"name":"20021123 acFTP Authentication Issue","tags":["mailing-list","x_refsource_VULNWATCH"],"url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0088.html"},{"name":"20021124 acFTP Authentication Issue","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/300929"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2002-2417","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"6235","refsource":"BID","url":"http://www.securityfocus.com/bid/6235"},{"name":"3334","refsource":"SREASON","url":"http://securityreason.com/securityalert/3334"},{"name":"acftp-authentication-bypass(10681)","refsource":"XF","url":"http://www.iss.net/security_center/static/10681.php"},{"name":"20021123 acFTP Authentication Issue","refsource":"VULNWATCH","url":"http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0088.html"},{"name":"20021124 acFTP Authentication Issue","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/300929"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2002-2417","datePublished":"2007-11-01T17:00:00.000Z","dateReserved":"2007-11-01T00:00:00.000Z","dateUpdated":"2024-08-08T04:06:53.859Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2002-12-31 05:00:00","lastModifiedDate":"2025-04-03 01:03:51","problem_types":["CWE-287","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:C/I:C/A:C","baseScore":10,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:acftp:acftp:1.4:*:*:*:*:*:*:*","matchCriteriaId":"253C00FC-5BA9-444E-B884-1CFAAAFDF380"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2002","CveId":"2417","Ordinal":"1","Title":"CVE-2002-2417","CVE":"CVE-2002-2417","Year":"2002"},"notes":[{"CveYear":"2002","CveId":"2417","Ordinal":"1","NoteData":"acFTP 1.4 does not properly handle when an invalid password is provided by the user during authentication, which allows remote attackers to hide or misrepresent certain activity from log files and possibly gain privileges.","Type":"Description","Title":"CVE-2002-2417"},{"CveYear":"2002","CveId":"2417","Ordinal":"2","NoteData":"2007-11-01","Type":"Other","Title":"Published"},{"CveYear":"2002","CveId":"2417","Ordinal":"3","NoteData":"2007-11-28","Type":"Other","Title":"Modified"}]}}}