CRITICAL🇵🇱 Wersja polska

CVE-2020-10288

CVSS 9.8v3.1pub. 2020-07-15upd. 2024-11-21

IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Abb Irb140

    HW
    Abb
    all versions
  • Abb Irc5

    HW
    Abb
    all versions
  • Abb Robotware

    APP
    Abb
    5.09
  • Windriver Vxworks

    OS
    Windriver
    5.5.1
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2020-35198CRITICAL9.8PL ✓same product

Integer overflow w alokatorze pamięci Wind River VxWorks 7 (calloc)

CVE-2021-29999CRITICAL9.8PL ✓same product

Stack overflow w serwerze DHCP systemu Wind River VxWorks

CVE-2021-29998CRITICAL9.8PL ✓same product

Heap overflow w kliencie DHCP systemu Wind River VxWorks

CVE-2016-20009CRITICAL9.8PL ✓same product

Stack-based buffer overflow w kliencie DNS Wind River VxWorks

CVE-2020-10287CRITICAL9.8PL ✓same product

Domyślne, publiczne poświadczenia w ABB IRC5 z usługą UAS