CVE-2020-37067
Last modified
CVE-2020-37067 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Filetto 1.0 FTP server contains a denial of service vulnerability in the FEAT command processing that allows attackers to crash the service. Attackers can send an oversized FEAT command with 11,008 bytes of repeated characters to trigger a buffer overflow and terminate the FTP service.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2020-37067?
How severe is CVE-2020-37067?
How do I fix CVE-2020-37067?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-37061BOOTP Turbo 2.0.1214 contains an unquoted service path vulne…8.5
- CVE-2020-37062DHCP Turbo 4.61298 contains an unquoted service path vulnera…8.5
- CVE-2020-37063TFTP Turbo 4.6.1273 contains an unquoted service path vulner…8.5
- CVE-2020-37064EPSON EasyMP Network Projection 2.81 contains an unquoted se…8.5
- CVE-2020-37065StreamRipper32 version 2.6 contains a buffer overflow vulner…9.8
- CVE-2020-37066GoldWave 5.70 contains a buffer overflow vulnerability that …9.8
- CVE-2020-37068Konica Minolta FTP Utility 1.0 contains a buffer overflow vu…9.8
- CVE-2020-37069Konica Minolta FTP Utility 1.0 contains a buffer overflow vu…9.8
- CVE-2020-3707Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultID…
- CVE-2020-37070CloudMe 1.11.2 contains a buffer overflow vulnerability that…9.8
- CVE-2020-37071CraftCMS 3 vCard Plugin 1.0.0 contains a deserialization vul…9.8
- CVE-2020-37072Victor CMS 1.0 contains a stored cross-site scripting vulner…6.1
Are you affected by CVE-2020-37067?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
