Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Psftp

First CVE: Nov 15, 2017Active for: 9 yearsTotal CVEs: 4

Psftp is a modestly scoped file-transfer utility whose vulnerability surface centers on the psftpd server component and reflects the authentication and input-handling demands of network protocol implementation. The recurring weakness classes include externally controlled resource references, improper authentication, input-validation gaps, insufficiently protected credentials, and use-after-free conditions, which collectively span authentication bypass, credential exposure, and memory-safety concerns. Current exploitation activity and exposure counts are shown alongside this summary.

FAUCET AI Generated
4
Total CVEs
More Total CVEs than 79% of tracked vendors
4.0
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 95% of tracked vendors
5.2
Avg CVSS Score
Higher Avg CVSS Score than 14% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Psftp over time

Volume of CVEsAvg CVSS Base Score
First CVE
Nov 15, 2017
8 years ago
Most Recent CVE
Nov 15, 2017
3,173 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (4 CVEs).

4 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2017-15271MEDIUM
A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did no
Nov 15, 20175.933NOYES
CVE-2017-15270MEDIUM
The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graph
Nov 15, 20175.330NOYES
CVE-2017-15272MEDIUM
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag
Nov 15, 20175.319NONO
CVE-2017-15269MEDIUM
The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server.
Nov 15, 20174.317NONO
View all 4 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products4 CVEs
100%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
Medium
Attack Vector
Local1 (25.0%)
Network3 (75.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low3 (75.0%)
High1 (25.0%)
Unknown0 (0.0%)
User Interaction
None4 (100.0%)
Unknown0 (0.0%)
Required0 (0.0%)
Privileges Required
Low2 (50.0%)
High0 (0.0%)
None2 (50.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (4 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
2 CVEs
50.0% of CVEs· 81st percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Psftp.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Psftp — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Psftp's Products

View all 1 CNAs →

Top CWEs