CVE-2020-5196
Last modified
CVE-2020-5196 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. EPSS estimates a 1.20% chance of exploitation in the next 30 days.
Description
Cerberus FTP Server Enterprise Edition prior to versions 11.0.3 and 10.0.18 allows an authenticated attacker to create files, display hidden files, list directories, and list files without the permission to zip and download (or unzip and upload) files. There are multiple ways to bypass certain permissions by utilizing the zip and unzip features. As a result, users without permission can see files, folders, and hidden files, and can create directories without permission.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Cerberusftp | Ftp Server | >= 10.0.0, < 10.0.18 |
| Cerberusftp | Ftp Server | >= 11.0.0, < 11.0.3 |
References
- https://support.cerberusftp.com/hc/en-us/community/topics/360000164199-AnnouncementsRelease Notes, Vendor Advisory
- https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilitiesExploit, Third Party Advisory
- https://support.cerberusftp.com/hc/en-us/community/topics/360000164199-AnnouncementsRelease Notes, Vendor Advisory
- https://www.doyler.net/security-not-included/cerberus-ftp-vulnerabilitiesExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-5196?
How severe is CVE-2020-5196?
How do I fix CVE-2020-5196?
Are you affected by CVE-2020-5196?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
