cbcvebase.
CVE-2020-9273
published 2020-02-20

CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c…

PriorityP260high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
12.04%
96.0th percentile
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux——
debiandebian_linux——
debiandebian_linux——
debianproftpd-dfsg< proftpd-dfsg 1.3.6c-2 (bookworm)proftpd-dfsg 1.3.6c-2 (bookworm)
fedoraprojectfedora——
fedoraprojectfedora——
opensusebackports_sle——
opensuseleap——
proftpdproftpd——
siemenssimatic_net_cp_1543-1_firmware< 3.03.0

Detection & IOCsextracted from sources · hover to see the quote

  • →The vulnerability is triggered by interrupting the data transfer channel in ProFTPD, causing a use-after-free in alloc_pool in pool.c — monitor for abrupt/abnormal FTP data channel disconnections followed by continued FTP command activity on the same session. ↗
  • →Restrict and monitor FTP control/data traffic on Port 21/TCP; unexpected interruptions of data transfers from low-privileged authenticated users should be treated as suspicious. ↗
  • →Track the upstream issue report for PoC details and indicators: https://github.com/proftpd/proftpd/issues/903 ↗
  • ·Exploitation requires a low-privileged (authenticated) user; unauthenticated exploitation is not indicated by the CVSS vector (PR:L). ↗
  • ·The embedded FTP server on affected Siemens SIMATIC CP devices is deactivated in the default configuration; attack surface only exists if FTP has been explicitly enabled. ↗
  • ·No known public exploits specifically target this vulnerability as of the advisory date. ↗
  • ·The vulnerability affects ProFTPD 1.3.7; fixed versions include 1.3.6c (Debian), 1.3.5e (EPEL-7 backport), and 1.3.3g (EPEL-6 backport) — ensure version checks account for these backported fixes. ↗

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.