First published: Tue Jun 07 2022(Updated: )
** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
FileZilla Client | =3.59.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29620 has been disputed by the vendor and is not officially classified as a vulnerability.
Since the vendor does not acknowledge CVE-2022-29620 as a vulnerability, there are currently no official fixes or mitigations available.
CVE-2022-29620 allows attackers to extract cleartext passwords of SSH or FTP servers through memory dumps.
CVE-2022-29620 specifically affects FileZilla Client version 3.59.0.
Users of FileZilla 3.59.0 should remain cautious and consider upgrading to newer versions if available.