ZeroHour

CVE-2020-26130

PoC
CVSS 3.1
7.8 high
EPSS
<1%p38
Published
()
Modified
Description

Issues were discovered in Open TFTP Server multithreaded 1.66 and Open TFTP Server single port 1.66. Due to insufficient access restrictions in the default installation directory, an attacker can elevate privileges by replacing the OpenTFTPServerMT.exe or the OpenTFTPServerSP.exe binary.

Vendors
open tftp server project
Products
open tftp server
Weakness
CWE-732
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.