CVE-2017-20203 describes a critical supply chain compromise affecting NetSarang Xmanager, Xshell, Xftp, and Xlpd products, where a malicious nssock2.dll library implemented a multi-stage, DNS-based backdoor. This backdoor, rated 9.3 Critical, allowed for remote code execution, data exfiltration, and persistence by contacting a C2 server via DNS TXT records to download and execute arbitrary code. Kaspersky Lab observed active exploitation in August 2017, although public exploit code and community discussion remain minimal. Patched versions were released by NetSarang to remediate this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| NetSarang Computer, Inc. | Xftp | 5.0 Build 1218CNA affecteddefault unaffected | |
| NetSarang Computer, Inc. | Xlpd | 5.0 Build 1220CNA affecteddefault unaffected | |
| NetSarang Computer, Inc. | Xmanager Enterprise | 5.0 Build 1232CNA affecteddefault unaffected | |
| NetSarang Computer, Inc. | Xmanager | 5.0 Build 1045CNA affecteddefault unaffected | |
| NetSarang Computer, Inc. | Xshell | 5.0 Build 1322CNA affecteddefault unaffected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.8 Bluesky, 0.5 Mastodon, and 1.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.
Remediation records are not available for this CVE.