CVE-2010-20122 is a critical stack-based buffer overflow vulnerability affecting Xftp FTP Client versions up to and including 3.0 (build 0238). It is triggered when the client receives an overly long directory string in response to a PWD command from a malicious FTP server. This flaw allows remote attackers to execute arbitrary code on the client system due to improper input validation. The vulnerability has a CVSS score of 9.3 (CRITICAL), indicating a severe risk. It is easily exploitable over the network with low attack complexity and no user interaction required, leading to high impact on confidentiality, integrity, and availability. The EPSS score of 0.54698 further highlights its significant exploitability. While not listed in CISA's KEV catalog, a Metasploit module exists for this vulnerability, confirming its exploitability. Community discussion is high with 14 mentions, suggesting active awareness and potential interest in this CVE, despite no reported active exploitation or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NetSarang Computer, Inc. | Xftp FTP Client | >= 0, <= 3.0 (build 0238)CNA affecteddefault unknown |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.