VulnerabilityModified
CVE-2020-14057
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations.
CRITICAL 9.8EPSS 2.58%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.58%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Monsta FTP 2.10.1 or below allows external control of paths used in filesystem operations. This allows attackers to read and write arbitrary local files, allowing an attacker to gain remote code execution in common deployments.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.58% probability · 84th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-610
- Affected
- monstaftp/monsta ftp
- Source
- cve@mitre.org
References
- https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_WriteThird Party Advisory
- https://www.monstaftp.com/notes/Release Notes, Vendor Advisory
- https://github.com/sbaresearch/advisories/tree/public/2019/SBA-ADV-20191203-01_Monsta_FTP_Arbitrary_File_Read_and_WriteThird Party Advisory
- https://www.monstaftp.com/notes/Release Notes, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.