cbcvebase.
CVE-2020-8284
published 2020-12-14

CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially…

PriorityP421low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
3.85%
89.0th percentile
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.

Affected

50 ranges· showing 25
VendorProductVersion rangeFixed in
applemac_os_x
applemac_os_x
applemac_os_x>= 10.14.0 < 10.14.610.14.6
applemac_os_x>= 10.15 < 10.15.710.15.7
applemacos
applemacos
applemacos
applemacos_big_sur
applesecurity_update_2021-002_catalina
debiancurl< curl 7.74.0-1 (bookworm)curl 7.74.0-1 (bookworm)
debiandebian_linux
debiandebian_linux
debianinetutils< inetutils 2:2.2-1 (bookworm)inetutils 2:2.2-1 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
fujitsum10-1_firmware< xcp2410xcp2410
fujitsum10-1_firmware< xcp3110xcp3110
fujitsum10-4_firmware< xcp2410xcp2410
fujitsum10-4_firmware< xcp3110xcp3110
fujitsum10-4s_firmware< xcp2410xcp2410
fujitsum10-4s_firmware< xcp3110xcp3110
fujitsum12-1_firmware< xcp2410xcp2410
fujitsum12-1_firmware< xcp3110xcp3110
fujitsum12-2_firmware< xcp2410xcp2410
fujitsum12-2_firmware< xcp3110xcp3110

CVSS provenance

nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian3.7LOW
vendor_msrc3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.