ZeroHour

CVE-2016-9499

PoC
CVSS 3.0
5.3 medium
EPSS
8%p94
Published
()
Modified
Description

Accellion FTP server prior to version FTA_9_12_220 only returns the username in the server response if the username is invalid. An attacker may use this information to determine valid user accounts and enumerate them.

Vendors
accellion
Products
ftp server
Weakness
CWE-204, CWE-200
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N

In the news

No ingested article mentions this CVE yet.