Executive brief
A vulnerability exists in certain Trivial File Transfer Protocol (TFTP) servers where the service is not restricted to a specific folder. This allows a remote attacker to download sensitive system files, such as password databases, from anywhere on the server's hard drive. This could lead to a complete compromise of the system and the theft of user credentials.
Technical details
The TFTP (Trivial File Transfer Protocol) daemon is misconfigured or lacks a 'chroot' or directory restriction mechanism. Because TFTP typically does not require authentication, a remote attacker can use standard TFTP GET commands to retrieve any file that the service process has permissions to read. This frequently includes sensitive files like /etc/passwd on Unix-like systems. The vulnerability is exploited over the network (UDP port 69) without any prior credentials or user interaction. Mitigation involves configuring the TFTP server to run in a secure, isolated directory (secure mode).
Affected products
- Generic TFTP Server
Timeline
- 1991-09-27: disclosed: Initial publication date in NVD