Psftp is a modestly scoped file-transfer utility whose vulnerability surface centers on the psftpd server component and reflects the authentication and input-handling demands of network protocol implementation. The recurring weakness classes include externally controlled resource references, improper authentication, input-validation gaps, insufficiently protected credentials, and use-after-free conditions, which collectively span authentication bypass, credential exposure, and memory-safety concerns. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Psftp over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2017-15271MEDIUM A use-after-free issue could be triggered remotely in the SFTP component of PSFTPd 10.0.4 Build 729. This issue could be triggered prior to authentication. The PSFTPd server did no | Nov 15, 2017 | 5.9 | 33 | NO | YES |
CVE-2017-15270MEDIUM The PSFTPd 10.0.4 Build 729 server does not properly escape data before writing it into a Comma Separated Values (CSV) file. This can be used by attackers to hide data in the Graph | Nov 15, 2017 | 5.3 | 30 | NO | YES |
CVE-2017-15272MEDIUM The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag | Nov 15, 2017 | 5.3 | 19 | NO | NO |
CVE-2017-15269MEDIUM The PSFTPd 10.0.4 Build 729 server does not prevent FTP bounce scans by default. These can be performed using "nmap -b" and allow performing scans via the FTP server. | Nov 15, 2017 | 4.3 | 17 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Psftp.
Media articles that mention a CVE ID that affects a product developed by Psftp — matched by CVE ID, not by vendor name.