📦

tftp_server

Vendor: d-link

Actively Exploited 0 CISA KEV List
PoC / Exploits 9 Code Available
Total RCEs 1 Remote Access
Total CVEs 2 Total Indexed
Avg. EPSS 16.11% Exploit Prob.
Latest CVE CVE-2023-29930 May 10

Security Vulnerability Index

Page 1 / 1
8.8 CVSS
CVE-2023-29930
RCE Exploit Found

An issue was found in Genesys CIC Polycom phone provisioning TFTP Server all version allows a remote attacker to execute arbitrary code via the login crednetials to the TFTP server configuration page.

EPSS: 2.01%
7.8 CVSS
CVE-2011-4722
Exploit Found

Directory traversal vulnerability in the TFTP Server 1.0.0.24 in Ipswitch WhatsUp Gold allows remote attackers to read arbitrary files via a .. (dot dot) in the Filename field of an RRQ operation.

EPSS: 57.60%
5.0 CVSS
CVE-2010-2310
Exploit Found

SolarWinds TFTP Server 10.4.0.13 allows remote attackers to cause a denial of service (crash) via a long write request.

EPSS: 11.02%
5.0 CVSS
CVE-2010-2115
Exploit Found

SolarWinds TFTP Server 10.4.0.10 allows remote attackers to cause a denial of service (no new connections) via a crafted read request.

EPSS: 55.95%
5.0 CVSS
CVE-2010-1174
Exploit Found

Cisco TFTP Server 1.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) read (aka RRQ) or (2) write (aka WRQ) request, or other TFTP packet. NOTE: some of these details are obtained from third party information.

EPSS: 5.08%
5.0 CVSS
CVE-2009-3115
Exploit Found

SolarWinds TFTP Server 9.2.0.111 and earlier allows remote attackers to cause a denial of service (service stop) via a crafted Option Acknowledgement (OACK) request. NOTE: some of these details are obtained from third party information.

EPSS: 10.66%
10.0 CVSS
CVE-2007-1435
Exploit Found

Buffer overflow in D-Link TFTP Server 1.0 allows remote attackers to cause a denial of service (crash) via a long (1) GET or (2) PUT request, which triggers memory corruption. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information.

EPSS: 42.82%
5.0 CVSS

Directory traversal vulnerability in SolarWinds TFTP Server 8.1 and earlier allows remote attackers to download arbitrary files via a crafted GET request including "....//" sequences, which are collapsed into "../" sequences by filtering.

EPSS: 4.02%
5.0 CVSS

Directory traversal vulnerability in WinAgents TFTP Server for Windows 3.1 and earlier allows remote attackers to read arbitrary files via "..." (triple dot) sequences in a GET request.

EPSS: 4.24%
5.0 CVSS

WinAgents TFTP Server 3.0 allows remote attackers to cause a denial of service (crash) via a request for a file with a long file name, possibly due to an off-by-one buffer overflow.

EPSS: 2.49%