H3-2022-0008
File Transfer Protocol (FTP) Port Exposed to the Internet
Category | SECURITY_MISCONFIGURATION |
Base Score | 3.0 |
Description
FTP, an application protocol that is not encrypted, is exposed to the internet.
Impact
Attackers often gain access to file servers through credential attacks by obtaining passwords leaked in data breaches and by password spraying weak passwords. This access allows attackers to steal or ransom off data contained within the file server. In some cases, file server access may allow an attacker to compromise the host.