Products: 1
    Vulnerabilities: 6
    Known Exploited: 0
    0
    Critical Level Threats
    3
    High Level Threats
    3
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2021-41634

    A user enumeration vulnerability in MELAG FTP Server 2.2.0.4 allows an attacker to identify valid FTP usernames.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022

    CVE-2021-41635

    When installed as Windows service MELAG FTP Server 2.2.0.4 is run as SYSTEM user, which grants remote attackers to abuse misconfigurations or vulnerabilities with administrative access over the entire host system.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022

    CVE-2021-41636

    MELAG FTP Server 2.2.0.4 allows an attacker to use the CWD command to break out of the FTP servers root directory and operate on the entire operating system, while the access restrictions of the user running the FTP server apply.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022

    CVE-2021-41637

    Weak access control permissions in MELAG FTP Server 2.2.0.4 allow the "Everyone" group to read the local FTP configuration file, which includes among other information the unencrypted passwords of all FTP users.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022

    CVE-2021-41638

    The authentication checks of the MELAG FTP Server in version 2.2.0.4 are incomplete, which allows a remote attacker to access local files only by using a valid username.

    Last Modified: Nov 21, 2024
    Published: Jun 24, 2022
    Items Per Page
    Melag Vulnerabilities & Security CVEs | CVE-DB