{ "schema_version": "1.4.0", "id": "GHSA-gf36-rwr4-jchr", "modified": "2022-05-17T02:07:00Z", "published": "2022-05-17T02:07:00Z", "aliases": [ "CVE-2010-2467" ], "details": "The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.", "severity": [], "affected": [], "references": [ { "type": "ADVISORY", "url": "https://nvd.nist.gov/vuln/detail/CVE-2010-2467" }, { "type": "WEB", "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/59828" }, { "type": "WEB", "url": "http://blip.tv/file/3414004" }, { "type": "WEB", "url": "http://www.darkreading.com/blog/archives/2010/04/attacking_door.html" }, { "type": "WEB", "url": "http://www.securityinfowatch.com/Executives+Columns+%2526+Features/1316527?pageNum=2" }, { "type": "WEB", "url": "http://www.slideshare.net/shawn_merdinger/we-dont-need-no-stinkin-badges-hacking-electronic-door-access-controllersquot-shawn-merdinger-carolinacon" } ], "database_specific": { "cwe_ids": [], "severity": "MODERATE", "github_reviewed": false, "github_reviewed_at": null, "nvd_published_at": "2010-06-25T21:30:00Z" } }