CVE-2020-37107: Core FTP LE 2.2 - Denial of Service
Core FTP LE 2.2 contains a denial of service vulnerability that allows attackers to crash the application by overwriting the account field with a large buffer. Attackers can create a text file with 20,000 repeated characters and paste it into the account field to cause the application to become unresponsive and require reinstallation.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-37107?
CVE-2020-37107 is classified as a denial of service vulnerability.
How do I fix CVE-2020-37107?
To fix CVE-2020-37107, update to the latest version of Core FTP LE that addresses the vulnerability.
What causes CVE-2020-37107?
CVE-2020-37107 is caused by an insufficient validation of input in the account field, allowing a large buffer to crash the application.
Who is affected by CVE-2020-37107?
CVE-2020-37107 affects users of Core FTP LE version 2.2.
Can CVE-2020-37107 be exploited remotely?
Yes, attackers can exploit CVE-2020-37107 remotely by inputting a large buffer string into the account field.