3Com.3CDaemon.FTP.Server.Information.Disclosure

description-logoDescription

It indicates a possible exploit of information disclosure vulnerability in 3Com 3CDaemon.


3CDaemon is a free TFTP, FTP, and Syslog daemon for Microsoft Windows platforms. A vulnerability is reported in it that allow an attacker retrieve information from server such as installation path A remote attackers to may sensitive information via a cd command that contains an MS-DOS device name, which reveals the installation path in an error message.

affected-products-logoAffected Products

3Com 3CDaemon 2.0 revision 10.

Impact logoImpact

Information disclosure leading to further attacks.

recomended-action-logoRecommended Actions

Apply appropriate patch from vendor if available.

Telemetry logoTelemetry

Coverage

IPS (Regular DB)
IPS (Extended DB)