CVE-2020-10288

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
15/07/2020
Last modified:
23/07/2020

Description

IRC5 exposes an ftp server (port 21). Upon attempting to gain access you are challenged with a request of username and password, however you can input whatever you like. As long as the field isn't empty it will be accepted.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:abb:robotware:5.09:*:*:*:*:*:*:*
cpe:2.3:h:abb:irb140:-:*:*:*:*:*:*:*
cpe:2.3:h:abb:irc5:-:*:*:*:*:*:*:*
cpe:2.3:o:windriver:vxworks:5.5.1:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools