Short Name |
TFTP:DIRECTORY:SOLAR-TFTP-TRVRS |
---|---|
Severity |
Major |
Recommended |
No |
Recommended Action |
Drop |
Category |
TFTP |
Keywords |
SolarWinds Directory Traversal |
Release Date |
2003/04/22 |
Update Number |
1213 |
Supported Platforms |
idp-4.0+, isg-3.0+, j-series-9.5+, mx-11.4+, srx-12.1+, srx-branch-12.1+, vmx-17.4+, vsrx-12.1+, vsrx3bsd-18.2+ |
This signature detects directory traversal attempts against the SolarWinds TFTP Server. All versions prior to 5.0.60 are vulnerable. A successful attack can allow attackers to retrieve sensitive system files and use the information to further compromise the TFTP Server.
SolarWinds TFTP Server is distributed for the Microsoft Windows platform. The SolarWinds TFTP Server does not properly handle user-supplied input. Due to insufficient handling of user input, it is possible for a remote user to request arbitrary files from the vulnerable server. It would be possible for a remote user to download any files readable through the permissions of the TFTP Server user.