Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
BID:38543
Info
Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
| Bugtraq ID: | 38543 |
| Class: | Failure to Handle Exceptional Conditions |
| CVE: |
CVE-2010-0962 |
| Remote: | Yes |
| Local: | No |
| Published: | Mar 04 2010 12:00AM |
| Updated: | Apr 13 2015 09:02PM |
| Credit: | Sabahattin Gucukoglu |
| Vulnerable: |
Apple Time Capsule Firmware 7.5 Apple Time Capsule Firmware 7.4.2 Apple Time Capsule 0 Apple Mac OS X Server 10.6.2 Apple Mac OS X Server 10.6.1 Apple Mac OS X Server 10.5.8 Apple Mac OS X Server 10.5.7 Apple Mac OS X Server 10.5.6 Apple Mac OS X Server 10.5.5 Apple Mac OS X Server 10.5.4 Apple Mac OS X Server 10.5.3 Apple Mac OS X Server 10.5.2 Apple Mac OS X Server 10.5.1 Apple Mac OS X Server 10.6 Apple Mac OS X Server 10.5 Apple Mac OS X 10.6.2 Apple Mac OS X 10.6.1 Apple Mac OS X 10.5.8 Apple Mac OS X 10.5.7 Apple Mac OS X 10.5.6 Apple Mac OS X 10.5.5 Apple Mac OS X 10.5.4 Apple Mac OS X 10.5.3 Apple Mac OS X 10.5.2 Apple Mac OS X 10.5.1 Apple Mac OS X 10.6 Apple Mac OS X 10.5 Apple AirPort Extreme Firmware 7.4.2 Apple AirPort Extreme Firmware 7.5 Apple Airport Extreme 0 Apple Airport Express 0 |
| Not Vulnerable: | |
Discussion
Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
Multiple Apple wireless products are prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform anonymous port scans on a victim's computer and send unsolicited emails and news. Other attacks are also possible.
The following products are affected:
Airport Express Firmware version 7.5
Airport Extreme Firmware version 7.5
Time Capsule Firmware version 7.5
Other products and versions may also be affected.
Multiple Apple wireless products are prone to a security-bypass vulnerability.
An attacker can exploit this issue to perform anonymous port scans on a victim's computer and send unsolicited emails and news. Other attacks are also possible.
The following products are affected:
Airport Express Firmware version 7.5
Airport Extreme Firmware version 7.5
Time Capsule Firmware version 7.5
Other products and versions may also be affected.
Exploit / POC
Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
An attacker can exploit this issue by using readily available network utilities.
An attacker can exploit this issue by using readily available network utilities.
Solution / Fix
Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
Multiple Apple Wireless Products FTP Port Forward Security Bypass Vulnerability
References:
References:
- Apple Homepage (Apple)
- Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy Provi (Sabahattin Gucukoglu
) - Re: Apple Airport Wireless Products: Promiscuous FTP PORT Allowed in FTP Proxy P (Sabahattin Gucukoglu
)