Cisco announced multiple vulnerabilities in the Cisco IOS FTP Server feature today. These vulnerabilities can result in denial of service, improper user verification, and the ability to retrieve or write any file to the device. This last vulnerability includes the saved configuration file which includes passwords. The Cisco IOS FTP Server feature is only available in a limited number of IOS releases and is disabled by default. Visit Cisco’s web site for more detailed information.
Multiple Vulnerabilities in the IOS FTP Server

Get Slaptijack updates delivered to your Inbox or RSS Reader for free!
Leave a Reply