CVE-2010-20115 is a critical memory corruption vulnerability affecting Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to 1.31. This flaw, stemming from an out-of-bounds array access during FTP PORT command parsing, allows an attacker to manipulate stack memory and potentially execute arbitrary code. With a CVSS score of 9.3 (CRITICAL), exploitation requires direct network access to the FTP service and is considered low complexity. While not actively exploited in the wild, a Metasploit module exists, and the vulnerability has garnered significant community discussion, indicating a high potential for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0, <= 1.31CPE match | cpe:2.3:a:arcane_software:vermillion_ftp_daemon:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.