CVE-2021-41639:MELAG FTP Server 2.2.0.4 stores unencrypted passwords of FTP users in a local configuration file, creating a significant security risk.

splash
Back

Description Preview

MELAG FTP Server version 2.2.0.4 has been identified with a critical security vulnerability (CWE-312: Cleartext Storage of Sensitive Information). The application stores FTP user credentials in plaintext within a local configuration file. This insecure practice allows any user with access to the configuration file to view the stored passwords, potentially leading to unauthorized access to the FTP server and its contents. This vulnerability compromises the confidentiality of user credentials and could lead to further system compromise.

Overview

The vulnerability in MELAG FTP Server 2.2.0.4 involves the storage of sensitive authentication credentials in cleartext format. When user accounts are created in the FTP server, their passwords are stored without encryption in a configuration file on the local system. This practice violates security best practices that require sensitive information like passwords to be stored using strong encryption or hashing algorithms. An attacker with access to the system file could easily extract valid user credentials, allowing them to authenticate to the FTP server and potentially access sensitive data or perform unauthorized operations.

Remediation

To address this vulnerability, the following measures are recommended:

  1. Update to a newer version of MELAG FTP Server if a patched version is available
  2. Implement password hashing using strong algorithms (such as bcrypt, Argon2, or PBKDF2) to store credentials
  3. Apply proper file system permissions to restrict access to configuration files
  4. Consider implementing multi-factor authentication for FTP access
  5. Regularly rotate passwords for all FTP accounts
  6. Monitor access logs for any suspicious activity
  7. Consider migrating to a more secure file transfer protocol such as SFTP or FTPS

References

  1. https://www.securesystems.de/blog/advisory-and-exploitation-the-melag-ftp-server/ - Contains detailed information about the vulnerability and exploitation techniques
  2. CWE-312: Cleartext Storage of Sensitive Information - https://cwe.mitre.org/data/definitions/312.html
  3. OWASP Secure Password Storage - https://cheatsheetseries.owasp.org/cheatsheets/Password_Storage_Cheat_Sheet.html

Industry ExposureMost to least
This section illustrates the prevalence of a specific Common Vulnerabilities and Exposures (CVE) across various industries based on customer reports. The ranking displays industries from the most to least affected by this particular vulnerability, offering valuable insight into where this CVE has been most frequently observed. This information can help organizations within these sectors prioritize their security efforts, understand their relative risk exposure compared to their peers, and focus remediation strategies where they are most needed. By understanding the industry-specific impact, organizations can make more informed decisions regarding patching, resource allocation, and overall risk management related to this CVE.

  1. Accommodation & Food Services
    Accommodation & Food Services
  2. Administrative, Support, Waste Management & Remediation Services
    Administrative, Support, Waste Management & Remediation Services
  3. Agriculture, Forestry Fishing & Hunting
    Agriculture, Forestry Fishing & Hunting
  4. Arts, Entertainment & Recreation
    Arts, Entertainment & Recreation
  5. Construction
    Construction
  6. Educational Services
    Educational Services
  7. Finance and Insurance
    Finance and Insurance
  8. Health Care & Social Assistance
    Health Care & Social Assistance
  9. Information
    Information
  10. Management of Companies & Enterprises
    Management of Companies & Enterprises
  11. Manufacturing
    Manufacturing
  12. Mining
    Mining
  13. Other Services (except Public Administration)
    Other Services (except Public Administration)
  14. Professional, Scientific, & Technical Services
    Professional, Scientific, & Technical Services
  15. Public Administration
    Public Administration
  16. Real Estate Rental & Leasing
    Real Estate Rental & Leasing
  17. Retail Trade
    Retail Trade
  18. Transportation & Warehousing
    Transportation & Warehousing
  19. Utilities
    Utilities
  20. Wholesale Trade
    Wholesale Trade

Focus on What Matters

  1. See Everything.
  2. Identify True Risk.
  3. Proactively Mitigate Threats.

Let's talk!

background
Armis Vulnerability Intelligence Database