CVE-2021-41639 describes a vulnerability in MELAG FTP Server 2.2.0.4 where unencrypted FTP user passwords are stored in a local configuration file. This medium-severity vulnerability (CVSS 5.5) requires local access and user privileges (AV:L/PR:L) to compromise the confidentiality of user credentials (C:H). While the EPSS score is very low and there is no known active exploitation, public exploit code, or significant community discussion, the exposure of plaintext passwords poses a clear risk to affected systems.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.2.0.4CPE matchmatch criteria | cpe:2.3:a:melag:ftp_server:2.2.0.4:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.