
Cloud Vulnerability DB
A community-led vulnerabilities database
SecureCRT before version 8.7.2 was discovered to contain a critical vulnerability (CVE-2020-12651) that allows remote attackers to execute arbitrary code. The vulnerability was identified through a combination of Integer Overflow and Buffer Overflow issues, specifically related to how the application handles banner processing that can trigger line numbers to CSI functions exceeding INT_MAX (NVD, CVE).
The vulnerability stems from an implementation flaw where a banner can trigger line numbers to CSI (Control Sequence Introducer) functions that exceed INT_MAX, leading to both Integer Overflow and Buffer Overflow conditions. This combination of vulnerabilities creates a critical security issue that could be exploited remotely (NVD). The vulnerability has been assigned a CVSS 3.0 score of 9.8 (Critical), indicating the highest severity level (ManageEngine).
The successful exploitation of this vulnerability could allow remote attackers to execute arbitrary code on the affected system. Given the critical CVSS score of 9.8, this vulnerability represents a severe security risk that could potentially lead to complete system compromise (ManageEngine).
The vulnerability can be exploited by remote attackers who can send specially crafted banners to trigger the integer and buffer overflow conditions. No authentication is required for exploitation, making this vulnerability particularly dangerous (NVD).
The vulnerability was addressed in SecureCRT version 8.7.2. Users of affected versions should upgrade to version 8.7.2 or later to mitigate this security risk. The fix was documented in VanDyke Software's product history and security advisory (VanDyke History, VanDyke Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."