VulnerabilityAnalyzed
CVE-2020-37068
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers.
HIGH 8.7EPSS 0.60%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.60%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Konica Minolta FTP Utility 1.0 contains a buffer overflow vulnerability in the LIST command that allows attackers to overwrite system registers. Attackers can send an oversized buffer of 1500 'A' characters to crash the FTP server and potentially execute unauthorized code.
- CVSS 4.0
- 8.7 HIGHCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/M
- EPSS
- 0.60% probability · 47th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-120
- Affected
- konicaminolta/ftp utility
- Source
- disclosure@vulncheck.com
References
- https://konica-minolta-ftp-utility.software.informer.com/download/Permissions Required
- https://www.exploit-db.com/exploits/48501Exploit, Third Party Advisory, VDB Entry
- https://www.konicaminolta.us/Product
- https://www.vulncheck.com/advisories/konica-minolta-ftp-utility-list-denial-of-serviceThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.