CVE-2020-8284

Published Dec 14, 2020

Last updated 3 months ago

Overview

Description
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Source
support@hackerone.com
NVD status
Modified
Products
curl, fedora, debian_linux, clustered_data_ontap, hci_management_node, solidfire, hci_storage_node, hci_bootstrap_os, mac_os_x, macos, communications_billing_and_revenue_management, communications_cloud_native_core_policy, essbase, peoplesoft_enterprise_peopletools, m10-1_firmware, m10-4_firmware, m10-4s_firmware, m12-1_firmware, m12-2_firmware, m12-2s_firmware, sinec_infrastructure_network_services, universal_forwarder

Risk scores

CVSS 3.1

Type
Primary
Base score
3.7
Impact score
1.4
Exploitability score
2.2
Vector string
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:N/A:N
Severity
LOW

CVSS 2.0

Type
Primary
Base score
4.3
Impact score
2.9
Exploitability score
8.6
Vector string
AV:N/AC:M/Au:N/C:P/I:N/A:N

Weaknesses

support@hackerone.com
CWE-200
nvd@nist.gov
NVD-CWE-noinfo

Social media

Hype score
Not currently trending

Configurations

References

Sources include official advisories and independent security research.