TFTP.GET.Shadow

description-logoDescription

It indicates an attempt to access the shadow file on a host running Trivial File Transfer Protocol (TFTP) service.


There is a long-known security hole in TFTP that allows any unauthenticated user to read any readable files and to write any writable files on a remote system. Attackers can take advantage of this to get sensitive system information.

affected-products-logoAffected Products

Any unprotected SunOS 3.x is vulnerable.

Impact logoImpact

Information leak may assist future attacks

recomended-action-logoRecommended Actions


Apply appropriate patches or Upgrade the system to the latest non-vulnerable version.

Coverage

IPS (Regular DB)
IPS (Extended DB)

Version Updates

Date Version Status Detail
2021-04-13 18.057
Modified
Sig Added