
Cloud Vulnerability DB
A community-led vulnerabilities database
A buffer overflow vulnerability was discovered in WinSCP version 5.17.8, identified as CVE-2020-28864. The vulnerability was reported on November 23, 2020, and allows a malicious FTP server to cause a denial of service or potentially have other unspecified impacts by sending a long file name response (NVD, AttackerKB).
The vulnerability is classified as a classic buffer overflow (CWE-120) that occurs when processing directory listing responses from FTP servers. The issue specifically manifests when handling long file names in the directory listing. The vulnerability received a CVSS v3.1 base score of 9.8 (Critical) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, indicating network accessibility with no required privileges or user interaction (NVD).
When successfully exploited, the vulnerability can cause the WinSCP application to crash, resulting in a denial of service condition. Additionally, there may be potential for other unspecified impacts, though these are not fully detailed in the available sources (NVD).
The vulnerability was confirmed to be reproducible specifically on Windows 7 systems, while Windows 10 systems were not affected. A proof of concept was developed that demonstrated the crash by simulating a malicious FTP server sending crafted responses (WinSCP Forum).
The vulnerability was fixed in WinSCP version 5.17.9. Users should upgrade to this or a later version to mitigate the vulnerability (WinSCP Tracker).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."