Vandyke develops a focused suite of terminal-emulation, file-transfer, and secure-shell server products including SecureCRT, AbsoluteFTP, and VShell, with observed vulnerabilities centered on memory-safety and data-integrity weaknesses such as buffer-boundary violations, integer overflow, and improper validation of integrity checks. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Vandyke over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48795MEDIUM The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packet | Dec 18, 2023 | 5.9 | 81 | NO | YES |
CVE-2011-5164HIGH Stack-based buffer overflow in VanDyke Software AbsoluteFTP 1.9.6 through 2.2.10 allows remote FTP servers to execute arbitrary code via a crafted file name in a LIST command respo | Sep 15, 2012 | 9.3 | 61 | NO | YES |
CVE-2022-28054CRITICAL Improper sanitization of trigger action scripts in VanDyke Software VShell for Windows v4.6.2 allows attackers to execute arbitrary code via a crafted value. | May 2, 2022 | 9.8 | 48 | NO | NO |
CVE-2020-12651CRITICAL SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions t | May 15, 2020 | 9.8 | 33 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Vandyke.
Media articles that mention a CVE ID that affects a product developed by Vandyke — matched by CVE ID, not by vendor name.