Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2014-2735

WinSCP before 5.5.3, when FTP with TLS is used, does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.7%
CVSS Severity
CVSS v2 Score 5.8
Products affected by CVE-2014-2735
  • Winscp » Winscp » Version: 2.0
    cpe:2.3:a:winscp:winscp:2.0
  • Winscp » Winscp » Version: 2.1
    cpe:2.3:a:winscp:winscp:2.1
  • Winscp » Winscp » Version: 2.2
    cpe:2.3:a:winscp:winscp:2.2
  • Winscp » Winscp » Version: 2.2.3
    cpe:2.3:a:winscp:winscp:2.2.3
  • Winscp » Winscp » Version: 2.3
    cpe:2.3:a:winscp:winscp:2.3
  • Winscp » Winscp » Version: 3.0
    cpe:2.3:a:winscp:winscp:3.0
  • Winscp » Winscp » Version: 3.1
    cpe:2.3:a:winscp:winscp:3.1
  • Winscp » Winscp » Version: 3.2
    cpe:2.3:a:winscp:winscp:3.2
  • Winscp » Winscp » Version: 3.2.1
    cpe:2.3:a:winscp:winscp:3.2.1
  • Winscp » Winscp » Version: 3.3
    cpe:2.3:a:winscp:winscp:3.3
  • Winscp » Winscp » Version: 3.4
    cpe:2.3:a:winscp:winscp:3.4
  • Winscp » Winscp » Version: 3.4.1
    cpe:2.3:a:winscp:winscp:3.4.1
  • Winscp » Winscp » Version: 3.4.2
    cpe:2.3:a:winscp:winscp:3.4.2
  • Winscp » Winscp » Version: 3.5
    cpe:2.3:a:winscp:winscp:3.5
  • Winscp » Winscp » Version: 3.5.5
    cpe:2.3:a:winscp:winscp:3.5.5
  • Winscp » Winscp » Version: 3.5.6
    cpe:2.3:a:winscp:winscp:3.5.6
  • Winscp » Winscp » Version: 3.6
    cpe:2.3:a:winscp:winscp:3.6
  • Winscp » Winscp » Version: 3.6.1
    cpe:2.3:a:winscp:winscp:3.6.1
  • Winscp » Winscp » Version: 3.6.5
    cpe:2.3:a:winscp:winscp:3.6.5
  • Winscp » Winscp » Version: 3.6.6
    cpe:2.3:a:winscp:winscp:3.6.6
  • Winscp » Winscp » Version: 3.6.7
    cpe:2.3:a:winscp:winscp:3.6.7
  • Winscp » Winscp » Version: 3.6.8
    cpe:2.3:a:winscp:winscp:3.6.8
  • Winscp » Winscp » Version: 3.7
    cpe:2.3:a:winscp:winscp:3.7
  • Winscp » Winscp » Version: 3.7.1
    cpe:2.3:a:winscp:winscp:3.7.1
  • Winscp » Winscp » Version: 3.7.2
    cpe:2.3:a:winscp:winscp:3.7.2
  • Winscp » Winscp » Version: 3.7.3
    cpe:2.3:a:winscp:winscp:3.7.3
  • Winscp » Winscp » Version: 3.7.4
    cpe:2.3:a:winscp:winscp:3.7.4
  • Winscp » Winscp » Version: 3.7.5
    cpe:2.3:a:winscp:winscp:3.7.5
  • Winscp » Winscp » Version: 3.7.6
    cpe:2.3:a:winscp:winscp:3.7.6
  • Winscp » Winscp » Version: 3.8
    cpe:2.3:a:winscp:winscp:3.8
  • Winscp » Winscp » Version: 3.8.1
    cpe:2.3:a:winscp:winscp:3.8.1
  • Winscp » Winscp » Version: 3.8.2
    cpe:2.3:a:winscp:winscp:3.8.2
  • Winscp » Winscp » Version: 3.8_beta
    cpe:2.3:a:winscp:winscp:3.8_beta
  • Winscp » Winscp » Version: 4.0
    cpe:2.3:a:winscp:winscp:4.0
  • Winscp » Winscp » Version: 4.0.1
    cpe:2.3:a:winscp:winscp:4.0.1
  • Winscp » Winscp » Version: 4.0.2
    cpe:2.3:a:winscp:winscp:4.0.2
  • Winscp » Winscp » Version: 4.0.3
    cpe:2.3:a:winscp:winscp:4.0.3
  • Winscp » Winscp » Version: 4.0.4
    cpe:2.3:a:winscp:winscp:4.0.4
  • Winscp » Winscp » Version: 4.0.5
    cpe:2.3:a:winscp:winscp:4.0.5
  • Winscp » Winscp » Version: 4.0.6
    cpe:2.3:a:winscp:winscp:4.0.6
  • Winscp » Winscp » Version: 4.0.7
    cpe:2.3:a:winscp:winscp:4.0.7
  • Winscp » Winscp » Version: 4.1
    cpe:2.3:a:winscp:winscp:4.1
  • Winscp » Winscp » Version: 4.1.1
    cpe:2.3:a:winscp:winscp:4.1.1
  • Winscp » Winscp » Version: 4.1.2
    cpe:2.3:a:winscp:winscp:4.1.2
  • Winscp » Winscp » Version: 4.1.3
    cpe:2.3:a:winscp:winscp:4.1.3
  • Winscp » Winscp » Version: 4.1.4
    cpe:2.3:a:winscp:winscp:4.1.4
  • Winscp » Winscp » Version: 4.1.5
    cpe:2.3:a:winscp:winscp:4.1.5
  • Winscp » Winscp » Version: 4.1.6
    cpe:2.3:a:winscp:winscp:4.1.6
  • Winscp » Winscp » Version: 4.1.7
    cpe:2.3:a:winscp:winscp:4.1.7
  • Winscp » Winscp » Version: 4.1.8
    cpe:2.3:a:winscp:winscp:4.1.8
  • Winscp » Winscp » Version: 4.1.9
    cpe:2.3:a:winscp:winscp:4.1.9
  • Winscp » Winscp » Version: 4.2
    cpe:2.3:a:winscp:winscp:4.2
  • Winscp » Winscp » Version: 4.2.1
    cpe:2.3:a:winscp:winscp:4.2.1
  • Winscp » Winscp » Version: 4.2.2
    cpe:2.3:a:winscp:winscp:4.2.2
  • Winscp » Winscp » Version: 4.2.3
    cpe:2.3:a:winscp:winscp:4.2.3
  • Winscp » Winscp » Version: 4.2.4
    cpe:2.3:a:winscp:winscp:4.2.4
  • Winscp » Winscp » Version: 4.2.5
    cpe:2.3:a:winscp:winscp:4.2.5
  • Winscp » Winscp » Version: 4.2.6
    cpe:2.3:a:winscp:winscp:4.2.6
  • Winscp » Winscp » Version: 4.2.7
    cpe:2.3:a:winscp:winscp:4.2.7
  • Winscp » Winscp » Version: 4.2.8
    cpe:2.3:a:winscp:winscp:4.2.8
  • Winscp » Winscp » Version: 4.2.9
    cpe:2.3:a:winscp:winscp:4.2.9
  • Winscp » Winscp » Version: 4.3
    cpe:2.3:a:winscp:winscp:4.3
  • Winscp » Winscp » Version: 4.3.1
    cpe:2.3:a:winscp:winscp:4.3.1
  • Winscp » Winscp » Version: 4.3.2
    cpe:2.3:a:winscp:winscp:4.3.2
  • Winscp » Winscp » Version: 4.3.3
    cpe:2.3:a:winscp:winscp:4.3.3
  • Winscp » Winscp » Version: 4.3.4
    cpe:2.3:a:winscp:winscp:4.3.4
  • Winscp » Winscp » Version: 4.3.5
    cpe:2.3:a:winscp:winscp:4.3.5
  • Winscp » Winscp » Version: 4.3.6
    cpe:2.3:a:winscp:winscp:4.3.6
  • Winscp » Winscp » Version: 4.3.7
    cpe:2.3:a:winscp:winscp:4.3.7
  • Winscp » Winscp » Version: 4.3.8
    cpe:2.3:a:winscp:winscp:4.3.8
  • Winscp » Winscp » Version: 4.3.9
    cpe:2.3:a:winscp:winscp:4.3.9
  • Winscp » Winscp » Version: 4.4
    cpe:2.3:a:winscp:winscp:4.4
  • Winscp » Winscp » Version: 4.4.0
    cpe:2.3:a:winscp:winscp:4.4.0
  • Winscp » Winscp » Version: 5.0
    cpe:2.3:a:winscp:winscp:5.0
  • Winscp » Winscp » Version: 5.0.1
    cpe:2.3:a:winscp:winscp:5.0.1
  • Winscp » Winscp » Version: 5.0.2
    cpe:2.3:a:winscp:winscp:5.0.2
  • Winscp » Winscp » Version: 5.0.3
    cpe:2.3:a:winscp:winscp:5.0.3
  • Winscp » Winscp » Version: 5.0.4
    cpe:2.3:a:winscp:winscp:5.0.4
  • Winscp » Winscp » Version: 5.0.5
    cpe:2.3:a:winscp:winscp:5.0.5
  • Winscp » Winscp » Version: 5.0.6
    cpe:2.3:a:winscp:winscp:5.0.6
  • Winscp » Winscp » Version: 5.0.7
    cpe:2.3:a:winscp:winscp:5.0.7
  • Winscp » Winscp » Version: 5.0.8
    cpe:2.3:a:winscp:winscp:5.0.8
  • Winscp » Winscp » Version: 5.0.9
    cpe:2.3:a:winscp:winscp:5.0.9
  • Winscp » Winscp » Version: 5.1
    cpe:2.3:a:winscp:winscp:5.1
  • Winscp » Winscp » Version: 5.1.1
    cpe:2.3:a:winscp:winscp:5.1.1
  • Winscp » Winscp » Version: 5.1.2
    cpe:2.3:a:winscp:winscp:5.1.2
  • Winscp » Winscp » Version: 5.1.3
    cpe:2.3:a:winscp:winscp:5.1.3
  • Winscp » Winscp » Version: 5.1.4
    cpe:2.3:a:winscp:winscp:5.1.4
  • Winscp » Winscp » Version: 5.1.5
    cpe:2.3:a:winscp:winscp:5.1.5
  • Winscp » Winscp » Version: 5.1.6
    cpe:2.3:a:winscp:winscp:5.1.6
  • Winscp » Winscp » Version: 5.1.7
    cpe:2.3:a:winscp:winscp:5.1.7
  • Winscp » Winscp » Version: 5.1.8
    cpe:2.3:a:winscp:winscp:5.1.8
  • Winscp » Winscp » Version: 5.2
    cpe:2.3:a:winscp:winscp:5.2
  • Winscp » Winscp » Version: 5.2.1
    cpe:2.3:a:winscp:winscp:5.2.1
  • Winscp » Winscp » Version: 5.2.2
    cpe:2.3:a:winscp:winscp:5.2.2
  • Winscp » Winscp » Version: 5.2.3
    cpe:2.3:a:winscp:winscp:5.2.3
  • Winscp » Winscp » Version: 5.2.4
    cpe:2.3:a:winscp:winscp:5.2.4
  • Winscp » Winscp » Version: 5.2.5
    cpe:2.3:a:winscp:winscp:5.2.5
  • Winscp » Winscp » Version: 5.2.6
    cpe:2.3:a:winscp:winscp:5.2.6
  • Winscp » Winscp » Version: 5.2.7
    cpe:2.3:a:winscp:winscp:5.2.7
  • Winscp » Winscp » Version: 5.5
    cpe:2.3:a:winscp:winscp:5.5
  • Winscp » Winscp » Version: 5.5.1
    cpe:2.3:a:winscp:winscp:5.5.1
  • Winscp » Winscp » Version: 5.5.2
    cpe:2.3:a:winscp:winscp:5.5.2


Contact Us

Shodan ® - All rights reserved