National Cyber Awareness System
Vulnerability Summary for CVE-2005-3296
Original release date:10/23/2005
Last revised:03/08/2011
Source:
US-CERT/NIST
Overview
The FTP server in HP-UX 10.20, B.11.00, and B.11.11, allows remote attackers to list arbitrary directories as root by running the LIST command before logging in.
Impact
CVSS Severity (version 2.0 incomplete approximation):
Impact Subscore:
10.0
Exploitability Subscore:
10.0
CVSS Version 2 Metrics:
Access Vector: Network exploitable
Access Complexity: Low
Authentication: Not required to exploit
Impact Type:Provides administrator access, Allows complete confidentiality, integrity, and availability violation; Allows unauthorized disclosure of information; Allows disruption of service
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving NIST webspace. We have provided these links to other web sites because they may have information that would be of interest to you. No inferences should be drawn on account of other sites being referenced, or not, from this page. There may be other web sites that are more appropriate for your purpose. NIST does not necessarily endorse the views expressed, or concur with the facts presented on these sites. Further, NIST does not endorse any commercial products that may be mentioned on these sites. Please address comments about this page to nvd@nist.gov.
External Source: BID
Name: 15138
External Source: MISC
Name: http://www.frsirt.com/exploits/20051019.hpux_ftpd_preauth_list.pm.php
External Source: HP
Name: SSRT051064
External Source: SECTRACK
Name: 1015158
External Source: HP
Name: SSRT051064
US Government Resource: oval:org.mitre.oval:def:767
Name: oval:org.mitre.oval:def:767
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:615
Name: oval:org.mitre.oval:def:615
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:593
Name: oval:org.mitre.oval:def:593
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:438
Name: oval:org.mitre.oval:def:438
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:421
Name: oval:org.mitre.oval:def:421
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:410
Name: oval:org.mitre.oval:def:410
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:1472
Name: oval:org.mitre.oval:def:1472
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:1439
Name: oval:org.mitre.oval:def:1439
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:1276
Name: oval:org.mitre.oval:def:1276
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:1212
Name: oval:org.mitre.oval:def:1212
Type: Tool Signature
US Government Resource: oval:org.mitre.oval:def:1029
Name: oval:org.mitre.oval:def:1029
Type: Tool Signature
References to Check Content
Identifier:oval:org.mitre.oval:def:593
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:615
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:1472
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:421
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:1029
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:438
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:1212
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:1439
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:410
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:1276
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Identifier:oval:org.mitre.oval:def:767
Check System:http://oval.mitre.org/XMLSchema/oval-definitions-5
Vulnerable software and versions
 | Configuration 1 |
 |  | OR |