CVE-2020-8284
published 2020-12-14CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially…
PriorityP421low3.7CVSS 3.1
AVNACHPRNUINSUCLINAN
EPSS
3.85%
89.0th percentile
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Affected
50 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| apple | mac_os_x | — | — |
| apple | mac_os_x | — | — |
| apple | mac_os_x | >= 10.14.0 < 10.14.6 | 10.14.6 |
| apple | mac_os_x | >= 10.15 < 10.15.7 | 10.15.7 |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos | — | — |
| apple | macos_big_sur | — | — |
| apple | security_update_2021-002_catalina | — | — |
| debian | curl | < curl 7.74.0-1 (bookworm) | curl 7.74.0-1 (bookworm) |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | inetutils | < inetutils 2:2.2-1 (bookworm) | inetutils 2:2.2-1 (bookworm) |
| fedoraproject | fedora | — | — |
| fedoraproject | fedora | — | — |
| fujitsu | m10-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4_firmware | < xcp3110 | xcp3110 |
| fujitsu | m10-4s_firmware | < xcp2410 | xcp2410 |
| fujitsu | m10-4s_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-1_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-1_firmware | < xcp3110 | xcp3110 |
| fujitsu | m12-2_firmware | < xcp2410 | xcp2410 |
| fujitsu | m12-2_firmware | < xcp3110 | xcp3110 |
CVSS provenance
nvdv3.13.7LOWCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian3.7LOW
vendor_msrc3.7LOW
vendor_redhat3.7LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
cisa_ics·2023-12-14
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
ICS Advisory
##
Siemens SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
Release DateDecember 14, 2023
Alert CodeICSA-23-348-10
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SIMATIC S7-1500 CPU 1518(F)-4 PN/DP MFP V3.1
- Vulnerabilities: Improper Restriction of XML External Entity Reference, Time-of-check Time-of-use (TOCTOU) Race Condition, Command Injection, Miss
CISA ICS
Siemens SINEC INS
cisa_ics·2022-03-10·CVSS 5.9
[MEDIUM] Siemens SINEC INS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens SINEC INS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 9.8
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC INS
- Vulnerability: Using Components with Known Vulnerabilities
## 2. RISK EVALUATION
Successful exploitation of this vulnerability in third-party components could allow an attacker to interfere with the affected product in various ways.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
Siemens reports this vulnerability affects the following SINEC INS (Infrastructure Netw
Apple
CVE-2020-8284: macOS Big Sur 11.3
vendor_apple·2021-04-26·CVSS 3.7
CVE-2020-8284 [LOW] CVE-2020-8284: macOS Big Sur 11.3
Apple Security Update: About the security content of macOS Big Sur 11.3
Product: macOS Big Sur
Version: 11.3
CVE: CVE-2020-8284
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A logic issue was addressed with improved state management.
Apple
CVE-2020-8284: Security Update 2021-002 Catalina
vendor_apple·2021-04-26·CVSS 3.7
CVE-2020-8284 [LOW] CVE-2020-8284: Security Update 2021-002 Catalina
Apple Security Update: About the security content of Security Update 2021-002 Catalina
Product: Security Update 2021-002 Catalina
CVE: CVE-2020-8284
Component: CoreText
Impact: Processing a maliciously crafted font may result in the disclosure of process memory
Description: A logic issue was addressed with improved state management.
Debian
CVE-2021-40491: inetutils - The ftp client in GNU Inetutils before 2.2 does not validate addresses returned ...
vendor_debian·2021·CVSS 3.7
CVE-2021-40491 [LOW] CVE-2021-40491: inetutils - The ftp client in GNU Inetutils before 2.2 does not validate addresses returned ...
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
Scope: local
bookworm: resolved (fixed in 2:2.2-1)
bullseye: resolved (fixed in 2:2.0-1+deb11u1)
forky: resolved (fixed in 2:2.2-1)
sid: resolved (fixed in 2:2.2-1)
trixie: resolved (fixed in 2:2.2-1)
Ubuntu
curl vulnerabilities
vendor_ubuntu·2020-12-09·CVSS 3.7
CVE-2020-8285 [LOW] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
USN-4665-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
Instructions: In general, a standard system update will make all t
Ubuntu
curl vulnerabilities
vendor_ubuntu·2020-12-09·CVSS 7.5
CVE-2020-8286 [HIGH] curl vulnerabilities
Title: curl vulnerabilities
Summary: Several security issues were fixed in curl.
Marc Aldorasi discovered that curl incorrectly handled the libcurl
CURLOPT_CONNECT_ONLY option. This could result in data being sent to the
wrong destination, possibly exposing sensitive information. This issue only
affected Ubuntu 20.10. (CVE-2020-8231)
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of serv
Red Hat
curl: FTP PASV command response can cause curl to connect to arbitrary host
vendor_redhat·2020-12-09·CVSS 3.7
CVE-2020-8284 [LOW] CWE-200 curl: FTP PASV command response can cause curl to connect to arbitrary host
curl: FTP PASV command response can cause curl to connect to arbitrary host
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
A malicious server can use the `PASV` response to trick curl into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions. If curl operates on a URL provided by a user, a user can exploit that and pass in a URL to a malicious FTP server
Microsoft
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about servi
vendor_msrc·2020-12-08·CVSS 3.7
CVE-2020-8284 [LOW] CWE-200 A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about servi
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port and this way potentially make curl extract information about services that are otherwise private and not disclosed for example doing port scanning and service banner extractions.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2
Debian
CVE-2020-8284: curl - A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlie...
vendor_debian·2020·CVSS 3.7
CVE-2020-8284 [LOW] CVE-2020-8284: curl - A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlie...
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Scope: local
bookworm: resolved (fixed in 7.74.0-1)
bullseye: resolved (fixed in 7.74.0-1)
forky: resolved (fixed in 7.74.0-1)
sid: resolved (fixed in 7.74.0-1)
trixie: resolved (fixed in 7.74.0-1)
GHSA
GHSA-qw8r-vcwc-vjc9: The ftp client in GNU Inetutils before 2
ghsa_unreviewed·2022-05-24·CVSS 3.7
CVE-2021-40491 [LOW] CWE-345 GHSA-qw8r-vcwc-vjc9: The ftp client in GNU Inetutils before 2
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
GHSA
GHSA-69rc-qfx4-h683: A malicious server can use the FTP PASV response to trick curl 7
ghsa_unreviewed·2022-05-24
CVE-2020-8284 [MEDIUM] CWE-200 GHSA-69rc-qfx4-h683: A malicious server can use the FTP PASV response to trick curl 7
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
OSV
CVE-2021-40491: The ftp client in GNU Inetutils before 2
osv·2021-09-03·CVSS 3.7
CVE-2021-40491 [LOW] CVE-2021-40491: The ftp client in GNU Inetutils before 2
The ftp client in GNU Inetutils before 2.2 does not validate addresses returned by PASV/LSPV responses to make sure they match the server address. This is similar to CVE-2020-8284 for curl.
OSV
CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7
osv·2020-12-14·CVSS 3.7
CVE-2020-8284 [LOW] CVE-2020-8284: A malicious server can use the FTP PASV response to trick curl 7
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
OSV
curl vulnerabilities
osv·2020-12-09·CVSS 7.5
CVE-2020-8231 [HIGH] curl vulnerabilities
curl vulnerabilities
Marc Aldorasi discovered that curl incorrectly handled the libcurl
CURLOPT_CONNECT_ONLY option. This could result in data being sent to the
wrong destination, possibly exposing sensitive information. This issue only
affected Ubuntu 20.10. (CVE-2020-8231)
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
It was discovered that curl incorrectly
OSV
curl vulnerabilities
osv·2020-12-09·CVSS 3.7
CVE-2020-8284 [LOW] curl vulnerabilities
curl vulnerabilities
USN-4665-1 fixed several vulnerabilities in curl. This update provides
the corresponding update for Ubuntu 12.04 ESM and Ubuntu 14.04 ESM.
Original advisory details:
Varnavas Papaioannou discovered that curl incorrectly handled FTP PASV
responses. An attacker could possibly use this issue to trick curl into
connecting to an arbitrary IP address and be used to perform port scanner
and other information gathering. (CVE-2020-8284)
It was discovered that curl incorrectly handled FTP wildcard matchins. A
remote attacker could possibly use this issue to cause curl to consume
resources and crash, resulting in a denial of service. (CVE-2020-8285)
No detection rules found.
No public exploits indexed.
HackerOne
[High] Arbitrary File Write via Path Traversal in cURL CLI (`-o`, `--output`) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)
hackerone·2025-06-30
[HIGH] [High] Arbitrary File Write via Path Traversal in cURL CLI (`-o`, `--output`) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)
[High] Arbitrary File Write via Path Traversal in cURL CLI (`-o`, `--output`) (CWE-22: Improper Limitation of a Pathname to a Restricted Directory)
## Summary:
The -o / --output parameter in cURL does not restrict or sanitize file paths. When passed relative traversal sequences (e.g., ../../), cURL writes files outside the current working directory, allowing arbitrary file overwrite. In automated or privileged environments (CI/CD, root containers), this leads to Remote Code Execution (RCE), privilege escalation, and supply chain risk.
This behavior violates path safety expectations when cURL is embedded in scripts or run with elevated privileges.
## Affected version
Affected Asset
Component: cURL CLI
Versions Affected: cURL 7.64.0 to 8.4.0 (Tested on 7.64.0, 7.79.1, 7.85.0, 8.4.0)
Tested
HackerOne
lib/net/ftp.rb: trusting PASV responses allow client abuse
hackerone·2021-07-08·CVSS 6.8
[MEDIUM] lib/net/ftp.rb: trusting PASV responses allow client abuse
lib/net/ftp.rb: trusting PASV responses allow client abuse
When `net/ftp` performs a passive FTP transfer, it tries to using PASV. Passive mode is what `net/ftp` uses by default.
A server response to a PASV command includes the (IPv4) address and port number for the client to connect back to in order to perform the actual data
transfer.
This is how the FTP protocol is designed to work.[^1]
A malicious server can use the PASV response to trick `net/ftp` into connecting back to a given IP address and port, and this way potentially make it extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
If `net/ftp` operates on a URL provided by a user (with by all means is an unwise setup), a user can exploit
Bugzilla
CVE-2021-31810 ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host
bugzilla·2021-07-07·CVSS 3.7
CVE-2021-31810 [LOW] CVE-2021-31810 ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host
CVE-2021-31810 ruby: FTP PASV command response can cause Net::FTP to connect to arbitrary host
A malicious FTP server can use the PASV response to trick Net::FTP into connecting back to a given IP address and port. This potentially makes Net::FTP extract information about services that are otherwise private and not disclosed (e.g., the attacker can conduct port scans and service banner extractions).
References:
https://www.ruby-lang.org/en/news/2021/07/07/trusting-pasv-responses-in-net-ftp/
Discussion:
This was fixed upstream in Ruby versions 3.0.2, 2.7.4, and 2.6.8:
https://www.ruby-lang.org/en/news/2021/07/07/ruby-3-0-2-released/
https://www.ruby-lang.org/en/news/2021/07/07/ruby-2-7-4-released/
https://www.ruby-lang.org/en/news/2021/07/07/ruby-2-6-8-released/
---
Upstream commit
HackerOne
CVE-2020-8284: trusting FTP PASV responses
hackerone·2021-02-09·CVSS 3.7
CVE-2020-8284 [LOW] CVE-2020-8284: trusting FTP PASV responses
CVE-2020-8284: trusting FTP PASV responses
## Summary:
The issue here arises from the fact that curl by default has the option CURLOPT_FTP_SKIP_PASV_IP disabled by default.
As a result, an attacker controlling the URL used by curl, can perform port scanning on behalf of the server where curl is running.
This can be achieved by setting up a custom FTP server that would setup the data channel through the PASV command using the port scanning target IP and port in the PASV connection info.
One good target for this issue are web applications vulnerable to SSRF.
## Steps To Reproduce:
So we can differentiate between open, closed and filtered ports with the following:
1. Open ports
curl will reply with TYPE after the PASV command
example:
Received: USER anonymous in 5
Received: PASS ftp@exampl
https://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2020-8284.htmlhttps://hackerone.com/reports/1040166https://lists.debian.org/debian-lts-announce/2020/12/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/https://security.gentoo.org/glsa/202012-14https://security.netapp.com/advisory/ntap-20210122-0007/https://support.apple.com/kb/HT212325https://support.apple.com/kb/HT212326https://support.apple.com/kb/HT212327https://www.debian.org/security/2021/dsa-4881https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.htmlhttps://cert-portal.siemens.com/productcert/pdf/ssa-389290.pdfhttps://curl.se/docs/CVE-2020-8284.htmlhttps://hackerone.com/reports/1040166https://lists.debian.org/debian-lts-announce/2020/12/msg00029.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/DAEHE2S2QLO4AO4MEEYL75NB7SAH5PSL/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/NZUVSQHN2ESHMJXNQ2Z7T2EELBB5HJXG/https://security.gentoo.org/glsa/202012-14https://security.netapp.com/advisory/ntap-20210122-0007/https://support.apple.com/kb/HT212325https://support.apple.com/kb/HT212326https://support.apple.com/kb/HT212327https://www.debian.org/security/2021/dsa-4881https://www.oracle.com//security-alerts/cpujul2021.htmlhttps://www.oracle.com/security-alerts/cpuApr2021.htmlhttps://www.oracle.com/security-alerts/cpuapr2022.htmlhttps://www.oracle.com/security-alerts/cpujan2022.html
2020-12-14
Published