CVE-2025-5331
קריטית 9.8
תיאור (מקור, אנגלית)
A vulnerability has been found in PCMan FTP Server 2.0.7 and classified as critical. This vulnerability affects unknown code of the component NLST Command Handler. The manipulation leads to buffer overflow. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.
מדדים
- CVSS 3.1
-
9.8 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H - CVSS 4.0
-
6.9 (MEDIUM)
מקור הציון: CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X - EPSS — סבירות ניצול
- 1% (אחוזון 100) נכון ל-20/9/2026
- CWE
- CWE-119, CWE-120
מוצרים מושפעים
pcman: ftp server
קישורים
- https://github.com/r3ng4f/PCMan_1/blob/main/exploit02.txt Exploit
- https://github.com/r3ng4f/PCMan_1/blob/main/exploit02.txt Exploit
- https://vuldb.com/?ctiid.310504 Permissions RequiredVDB Entry
- https://vuldb.com/?id.310504 Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.585404 Third Party AdvisoryVDB Entry