CVE-2020-37069
CRITICAL Exploitation: PoC
9.8
CVSS 3.1
Description
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the NLST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.
Metadata
Severity & Metrics
9.8
CRITICAL CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
SSVC — CISA Coordinator
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Konica Minolta | FTP Utility | — | 1.0 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| CWE-120 | cna | Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') |
CVSS scores (2)
| Score | Severity | Version | Source | Vector |
|---|---|---|---|---|
| 9.8 | CRITICAL | 3.1 | cna | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| 8.7 | HIGH | 4.0 | cna | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N |
References (4)
- ExploitDB-48502 https://www.exploit-db.com/exploits/48502
- Konica Minolta FTP Utility Download Page https://konica-minolta-ftp-utility.software.informer.com/download/
- Konica Minolta Vendor Homepage https://www.konicaminolta.us/
- VulnCheck Advisory: Konica Minolta FTP Utility 1.0 - 'NLST' Denial of Service https://www.vulncheck.com/advisories/konica-minolta-ftp-utility-nlst-denial-of-service