search menu icon-carat-right cmu-wordmark

CERT Coordination Center

Hewlett-Packard Company MPE/iX FTPSRVR does not properly validate certain commands

Vulnerability Note VU#551683

Original Release Date: 2003-08-19 | Last Revised: 2003-08-19

Overview

A vulnerability in the FTP server included with the MPE/iX operating system may allow a remote attacker to gain unauthorized access.

Description

MPE/iX is an operating system produced by Hewlett-Packard Company. The FTP server included with MPE/iX (FTPSRVR) contains a vulnerability which may allow a remote attacker to gain unauthorized access to the system.

Impact

A remote attacker may be able to gain unauthorized access to a vulnerable system.

Solution

Apply a patch as described in Hewlett Packard Security Bulletin HPSBMP0204-014.

Vendor Information

551683
 

CVSS Metrics

Group Score Vector
Base
Temporal
Environmental

References

Acknowledgements

Thanks to Hewlett-Packard Company for reporting this vulnerability.

This document was written by Ian A. Finlay.

Other Information

CVE IDs: CVE-2002-0610
Severity Metric: 28.35
Date Public: 2002-05-01
Date First Published: 2003-08-19
Date Last Updated: 2003-08-19 14:47 UTC
Document Revision: 6

Sponsored by CISA.