5.5
CVSSv3

CVE-2020-6857

Published: 21/01/2020 Updated: 18/04/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.

Most Upvoted Vulmon Research Post

There is no Researcher post for this vulnerability
Would you like to share something about it? Sign up now to share your knowledge with the community.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

taskautomation carbonftp 1.4

Mailing Lists

[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/NEOWISE-CARBONFTP-v14-INSECURE-PROPRIETARY-PASSWORD-ENCRYPTIONtxt [+] twittercom/hyp3rlinx [+] ISR: ApparitionSec [Vendor] wwwneowisecom [Product] CarbonFTP v14 CarbonFTP is a file synchronizati ...
Neowise CarbonFTP version 14 suffers from an insecure proprietary password encryption implementation ...
Neowise CarbonFTP version 14 suffers from an insecure proprietary password encryption implementation Second version of this exploit that is updated to work with Python 3 ...
Updated, exploit PoC had a check for an unused module was testing and removed, had two versions but previously sent the wrong one [+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/NEOWISE-CARBONFTP-v14-INSECURE-PROPRIETARY-PASSWORD-ENCRYPTIONtxt [+] twittercom/hy ...
[+] Credits: John Page (aka hyp3rlinx) [+] Website: hyp3rlinxaltervistaorg [+] Source: hyp3rlinxaltervistaorg/advisories/NEOWISE-CARBONFTP-v14-INSECURE-PROPRIETARY-PASSWORD-ENCRYPTIONtxt [+] twittercom/hyp3rlinx [+] ISR: ApparitionSec [Vendor] wwwneowisecom [Product] CarbonFTP v14 CarbonFTP is a file synchronization tool that ...