Advisories

SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service

Go Back
severity
medium
date
Affecting
  • SmartFTP Client 10.0.2909.0 (32 and 64 bit)

CWE
  • CWE-770 Allocation of Resources Without Limits or Throttling
CVSS
4.6
CVSS V4 Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
Credit
Eric Salario
Description
SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface.