Impact
The vulnerability allows an attacker to initiate an FTP passive data connection that is not bound to the authenticated control session, potentially enabling data transfer without proper authentication. This flaw could expose sensitive data or allow unauthorized manipulation of data streams. The weakness corresponds to CWE-923, reflecting the lack of session binding.
Affected Systems
The issue affects NetX Duo from the Eclipse Foundation. No specific version information is supplied; all releases of NetX Duo are potentially impacted until a patch is applied.
Risk and Exploitability
The CVSS score of 6 indicates a medium severity. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog, suggesting a lower likelihood of widespread exploitation at present. The likely attack vector is remote, exploiting the FTP protocol over a network to establish a data connection misassociated with the control session.
OpenCVE Enrichment