Headline
FedEx Ship Manager (FSM) 3704 Insecure .NET Remoting
FedEx Ship Manager (FSM) version 3704 suffers from an insecure use of .NET remoting.
Change Mirror Download
Vulnerable Software Download URL:https://www.fedex.com/en-us/shipping/ship-manager/software.html#tab-4FSM 3704 (and some earlier versions) use .NET Remoting in a way that canlead to unauthenticated remote code execution attacks as SYSTEM. Tools thatcan successfully attack affected services are freely available.Administrators should block or otherwise limit access to TCP ports openedby services installed by this software wherever possible.