CRITICAL🇵🇱 Wersja polska

CVE-2010-20115

CVSS 9.3v4.0pub. 2025-08-21upd. 2026-04-15

Arcane Software’s Vermillion FTP Daemon (vftpd) versions up to and including 1.31 contains a memory corruption vulnerability triggered by a malformed FTP PORT command. The flaw arises from an out-of-bounds array access during input parsing, allowing an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation requires direct access to the FTP service and is constrained by a single execution attempt if the daemon is installed as a Windows service.

🤖 AI Analysis
How it works

The vulnerability results from out-of-bounds array access during parsing of the FTP PORT command input, which is classified as improper type conversion error (CWE-704) and buffer overflow/out-of-bounds write (CWE-787). This allows an attacker to manipulate stack memory and potentially execute arbitrary code. Exploitation of the vulnerability requires direct network access to the FTP service and is limited to one exploitation attempt if the daemon runs as a Windows system service.

Impact

An attacker with network access to the FTP service can cause arbitrary code execution (RCE) on the vulnerable server, resulting in complete system compromise. Loss of confidentiality, integrity, and data availability is possible.

Mitigation & patch

Apply patches available from the vendor according to the references. Due to lack of information about a newer secure version, it is recommended to consider migration to alternative, actively supported FTP server software and restrict access to the FTP service only to trusted IP addresses using a firewall.

Who is affected

Arcane Software Vermillion FTP Daemon (vftpd) in versions up to 1.31 inclusive, running on Windows systems.

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCEMemory
CWE
References