cbcvebase.
CVE-2020-9273
published 2020-02-20

CVE-2020-9273: In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c…

PriorityP259high8.8CVSS 3.1
AVNACLPRLUINSUCHIHAH
EPSS
12.04%
95.7th percentile
In ProFTPD 1.3.7, it is possible to corrupt the memory pool by interrupting the data transfer channel. This triggers a use-after-free in alloc_pool in pool.c, and possible remote code execution.

Affected

10 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debiandebian_linux
debiandebian_linux
debianproftpd-dfsg< proftpd-dfsg 1.3.6c-2 (bookworm)proftpd-dfsg 1.3.6c-2 (bookworm)
fedoraprojectfedora
fedoraprojectfedora
opensusebackports_sle
opensuseleap
proftpdproftpd
siemenssimatic_net_cp_1543-1_firmware< 3.03.0

Detection & IOCsextracted from sources · hover to see the quote

  • The vulnerability is triggered by interrupting the data transfer channel in ProFTPD, causing a use-after-free in alloc_pool in pool.c — monitor for abrupt/abnormal FTP data channel disconnections followed by continued FTP command activity on the same session.
  • Restrict and monitor FTP control/data traffic on Port 21/TCP; unexpected interruptions of data transfers from low-privileged authenticated users should be treated as suspicious.
  • Track the upstream issue report for PoC details and indicators: https://github.com/proftpd/proftpd/issues/903
  • ·Exploitation requires a low-privileged (authenticated) user; unauthenticated exploitation is not indicated by the CVSS vector (PR:L).
  • ·The embedded FTP server on affected Siemens SIMATIC CP devices is deactivated in the default configuration; attack surface only exists if FTP has been explicitly enabled.
  • ·No known public exploits specifically target this vulnerability as of the advisory date.
  • ·The vulnerability affects ProFTPD 1.3.7; fixed versions include 1.3.6c (Debian), 1.3.5e (EPEL-7 backport), and 1.3.3g (EPEL-6 backport) — ensure version checks account for these backported fixes.

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.09.0CRITICALAV:N/AC:L/Au:S/C:C/I:C/A:C
osv8.8HIGH
vendor_debian8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.