ProFTPD < 1.2.11 Remote User Enumeration

medium Nessus Network Monitor Plugin ID 2393

Synopsis

The remote host may give an attacker information useful for future attacks.

Description

The remote ProFTPd server is as old or older than 1.2.10.
It is possible to determine which user names are valid on the remote host based on timing analysis attack of the login procedure.
An attacker may use this flaw to set up a list of valid usernames for a more efficient brute-force attack against the remote host.

Solution

Upgrade to version 1.2.11 or higher.

Plugin Details

Severity: Medium

ID: 2393

Family: FTP Servers

Published: 11/6/2004

Updated: 3/6/2019

Nessus ID: 15484

Risk Information

VPR

Risk Factor: Medium

Score: 4.2

CVSS v2

Risk Factor: Medium

Base Score: 5

Temporal Score: 4.5

Vector: CVSS2#AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS v3

Risk Factor: Medium

Base Score: 5.3

Temporal Score: 5

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

Temporal Vector: CVSS:3.0/E:F/RL:W/RC:X

Vulnerability Information

CPE: cpe:/a:proftpd_project:proftpd

Reference Information

CVE: CVE-2004-1602

BID: 11430