Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The FTP proxy server in Apple AirPort Express, AirPort Extreme, and Time Capsule with firmware 7.5 does not restrict the IP address and port specified in a PORT command from a client, which allows remote attackers to leverage intranet FTP servers for arbitrary TCP forwarding via a crafted PORT command.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Apple AirPort FTP端口转发绕过安全限制漏洞
Vulnerability Description
Apple AirPort设备是一款无线访问接入点,可为网络客户端提供802.11服务。 Apple AirPort等无线产品中内嵌的FTP代理服务器没有限制客户端在PORT命令中所指定的IP地址和端口,这允许远程攻击者利用内网FTP服务器转发任意TCP。 这个漏洞直接的影响是对于向内部客户端提供NAT的Airpor产品,能够访问这些产品外部所转发FTP端口的用户可以通过向任意地址和端口发送数据在NAT内执行FTP服务器操作。
CVSS Information
N/A
Vulnerability Type
N/A