info: name: Linux Anonymous FTP Access Enabled - Security Misconfiguration author: songyaeji severity: high description: > If the anonymous FTP account is enabled, malicious users may exploit it to login anonymously and write to directories, potentially gaining unauthorized access or executing local exploits against the system. This template checks for signs that anonymous FTP is enabled via /etc/passwd, vsFTPD, or ProFTPD configuration files. reference: - https://isms.kisa.or.kr - Cloud Vulnerability Assessment Guide(2024) by KISA tags: linux,ftp,anonymous,vsftpd,proftpd,misconfiguration,local metadata: verified: true os: linux max-request: 1 classification: cvss-metrics: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H cvss-score: 8.6 cwe-id: CWE-200