The default configuration of Cerberus FTP Server before 5.0.4.0 supports the DES cipher for SSH sessions, which makes it easier for remote attackers to obtain sensitive information by sniffing the network and performing a brute-force attack on the encrypted data.
References
Configurations
Configuration 1 (hide)
|
Information
Published : 2012-10-04 12:55
Updated : 2017-08-28 18:32
NVD link : CVE-2012-5301
Mitre link : CVE-2012-5301
JSON object : View
CWE
CWE-310
Cryptographic Issues
Products Affected
cerberusftp
- ftp_server