5.5
CVSSv3

CVE-2020-6857

Published: 21/01/2020 Updated: 18/04/2022
CVSS v2 Base Score: 2.1 | Impact Score: 2.9 | Exploitability Score: 3.9
CVSS v3 Base Score: 5.5 | Impact Score: 3.6 | Exploitability Score: 1.8
VMScore: 187
Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

CarbonFTP v1.4 uses insecure proprietary password encryption with a hard-coded weak encryption key. The key for local FTP server passwords is hard-coded in the binary.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

taskautomation carbonftp 1.4

Exploits

Neowise CarbonFTP version 14 suffers from an insecure proprietary password encryption implementation Second version of this exploit that is updated to work with Python 3 ...
Neowise CarbonFTP version 14 suffers from an insecure proprietary password encryption implementation ...

Mailing Lists

<!--X-Body-Begin--> <!--X-User-Header--> Full Disclosure mailing list archives <!--X-User-Header-End--> <!--X-TopPNI--> By Date By Thread </form> <!--X-TopPNI-End--> <!--X-MsgBody--> <!--X-Subject-Header-Begin--> Neowise CarbonFTP v14 / Insecure Proprietary Password Encryption / CVE-2020-6857 <!--X-Subject-Header-End--> <!--X-He ...