CVE-2019-9649 is a directory traversal vulnerability affecting the SFTP Server component in Core FTP 2.0 Build 674. A remote attacker can leverage the MDTM FTP command with a "..\..\" sequence to browse outside the configured root directory, allowing them to determine the existence and last modified date of files on the underlying operating system. This vulnerability has a medium severity CVSS score of 5.3, indicating low impact on confidentiality and no impact on integrity or availability, with no authentication required. While not actively exploited in the wild (no KEV entry), public exploit code is available via ExploitDB, and it has a high FAUCET Risk Score of 96/100 despite minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.0CPE matchmatch criteria | cpe:2.3:a:coreftp:core_ftp:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.