Fortra Globalscape EFT's administration server suffers from an information disclosure vulnerability where the serial number of the harddrive that Globalscape is installed on can be remotely determined via a "trial extension request" message
References
Configurations
History
21 Nov 2024, 07:59
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://kb.globalscape.com/Knowledgebase/11589/Is-EFT-susceptible-to-the-Remotely-obtain-HDD-serial-number-vulnerability - Vendor Advisory | |
| References | () https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/ - Exploit, Third Party Advisory |
30 Jun 2023, 19:28
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Globalscape eft Server
Globalscape |
|
| CWE | NVD-CWE-noinfo | |
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.3 |
| CPE | cpe:2.3:a:globalscape:eft_server:*:*:*:*:*:*:*:* | |
| References | (MISC) https://kb.globalscape.com/Knowledgebase/11589/Is-EFT-susceptible-to-the-Remotely-obtain-HDD-serial-number-vulnerability - Vendor Advisory | |
| References | (MISC) https://www.rapid7.com/blog/post/2023/06/22/multiple-vulnerabilities-in-fortra-globalscape-eft-administration-server-fixed/ - Exploit, Third Party Advisory |
22 Jun 2023, 20:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2023-06-22 20:15
Updated : 2024-11-21 07:59
NVD link : CVE-2023-2991
Mitre link : CVE-2023-2991
CVE.ORG link : CVE-2023-2991
JSON object : View
Products Affected
globalscape
- eft_server
CWE
