ArGoSoft FTP Server USER Command Account Enumeration

medium Nessus Plugin ID 16094

Synopsis

The remote FTP server is vulnerable to an information disclosure attack.

Description

The remote host is running the ArGoSoft FTP Server.

The remote version of this software returns different error messages when a user attempts to log in using a nonexistent username or a bad password.

An attacker may exploit this flaw to launch a dictionary attack against the remote host in order to obtain a list of valid user names.

Solution

Upgrade to ArGoSoft FTP 1.4.2.2 or newer.

See Also

http://www.nessus.org/u?501c2e30

Plugin Details

Severity: Medium

ID: 16094

File Name: argosoft_user_disclosure.nasl

Version: 1.24

Type: remote

Family: FTP

Published: 1/3/2005

Updated: 11/5/2018

Risk Information

CVSS Score Rationale: Score from a more in depth analysis done by tenable

VPR

Risk Factor: Low

Score: 1.4

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 3.7

Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Temporal Vector: E:U/RL:OF/RC:C

CVSS Score Source: CVE-2004-1428

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 4.6

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: E:U/RL:O/RC:C

Vulnerability Information

Exploit Ease: No known exploits are available

Vulnerability Publication Date: 10/27/2004

Reference Information

CVE: CVE-2004-1428

BID: 12139