Vulnerability Details CVE-2020-8284
A malicious server can use the FTP PASV response to trick curl 7.73.0 and earlier into connecting back to a given IP address and port, and this way potentially make curl extract information about services that are otherwise private and not disclosed, for example doing port scanning and service banner extractions.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 26.2%
CVSS Severity
CVSS v3 Score 3.7
CVSS v2 Score 4.3
Products affected by CVE-2020-8284
-
-
-
-
-
-
-
cpe:2.3:a:haxx:curl:6.3.1
-
-
-
cpe:2.3:a:haxx:curl:6.5.1
-
cpe:2.3:a:haxx:curl:6.5.2
-
-
cpe:2.3:a:haxx:curl:7.1.1
-
-
cpe:2.3:a:haxx:curl:7.10.1
-
cpe:2.3:a:haxx:curl:7.10.2
-
cpe:2.3:a:haxx:curl:7.10.3
-
cpe:2.3:a:haxx:curl:7.10.4
-
cpe:2.3:a:haxx:curl:7.10.5
-
cpe:2.3:a:haxx:curl:7.10.6
-
cpe:2.3:a:haxx:curl:7.10.7
-
cpe:2.3:a:haxx:curl:7.10.8
-
cpe:2.3:a:haxx:curl:7.11.0
-
cpe:2.3:a:haxx:curl:7.11.1
-
cpe:2.3:a:haxx:curl:7.11.2
-
cpe:2.3:a:haxx:curl:7.12.0
-
cpe:2.3:a:haxx:curl:7.12.1
-
cpe:2.3:a:haxx:curl:7.12.2
-
cpe:2.3:a:haxx:curl:7.12.3
-
cpe:2.3:a:haxx:curl:7.13.0
-
cpe:2.3:a:haxx:curl:7.13.1
-
cpe:2.3:a:haxx:curl:7.13.2
-
cpe:2.3:a:haxx:curl:7.14.0
-
cpe:2.3:a:haxx:curl:7.14.1
-
cpe:2.3:a:haxx:curl:7.15.0
-
cpe:2.3:a:haxx:curl:7.15.1
-
cpe:2.3:a:haxx:curl:7.15.2
-
cpe:2.3:a:haxx:curl:7.15.3
-
cpe:2.3:a:haxx:curl:7.15.4
-
cpe:2.3:a:haxx:curl:7.15.5
-
cpe:2.3:a:haxx:curl:7.16.0
-
cpe:2.3:a:haxx:curl:7.16.1
-
cpe:2.3:a:haxx:curl:7.16.2
-
cpe:2.3:a:haxx:curl:7.16.3
-
cpe:2.3:a:haxx:curl:7.16.4
-
cpe:2.3:a:haxx:curl:7.17.0
-
cpe:2.3:a:haxx:curl:7.17.1
-
cpe:2.3:a:haxx:curl:7.18.0
-
cpe:2.3:a:haxx:curl:7.18.1
-
cpe:2.3:a:haxx:curl:7.18.2
-
cpe:2.3:a:haxx:curl:7.19.0
-
cpe:2.3:a:haxx:curl:7.19.1
-
cpe:2.3:a:haxx:curl:7.19.2
-
cpe:2.3:a:haxx:curl:7.19.3
-
cpe:2.3:a:haxx:curl:7.19.4
-
cpe:2.3:a:haxx:curl:7.19.5
-
cpe:2.3:a:haxx:curl:7.19.6
-
cpe:2.3:a:haxx:curl:7.19.7
-
cpe:2.3:a:haxx:curl:7.19.7-53
-
-
cpe:2.3:a:haxx:curl:7.2.1
-
cpe:2.3:a:haxx:curl:7.20.0
-
cpe:2.3:a:haxx:curl:7.20.1
-
cpe:2.3:a:haxx:curl:7.21.0
-
cpe:2.3:a:haxx:curl:7.21.1
-
cpe:2.3:a:haxx:curl:7.21.2
-
cpe:2.3:a:haxx:curl:7.21.3
-
cpe:2.3:a:haxx:curl:7.21.4
-
cpe:2.3:a:haxx:curl:7.21.5
-
cpe:2.3:a:haxx:curl:7.21.6
-
cpe:2.3:a:haxx:curl:7.21.7
-
cpe:2.3:a:haxx:curl:7.22.0
-
cpe:2.3:a:haxx:curl:7.23.0
-
cpe:2.3:a:haxx:curl:7.23.1
-
cpe:2.3:a:haxx:curl:7.24.0
-
cpe:2.3:a:haxx:curl:7.25.0
-
cpe:2.3:a:haxx:curl:7.26.0
-
cpe:2.3:a:haxx:curl:7.27.0
-
cpe:2.3:a:haxx:curl:7.28.0
-
cpe:2.3:a:haxx:curl:7.28.1
-
cpe:2.3:a:haxx:curl:7.29.0
-
-
cpe:2.3:a:haxx:curl:7.30.0
-
cpe:2.3:a:haxx:curl:7.31.0
-
cpe:2.3:a:haxx:curl:7.32.0
-
cpe:2.3:a:haxx:curl:7.33.0
-
cpe:2.3:a:haxx:curl:7.34.0
-
cpe:2.3:a:haxx:curl:7.35.0
-
cpe:2.3:a:haxx:curl:7.36.0
-
cpe:2.3:a:haxx:curl:7.37.0
-
cpe:2.3:a:haxx:curl:7.37.1
-
cpe:2.3:a:haxx:curl:7.38.0
-
cpe:2.3:a:haxx:curl:7.39.0
-
-
cpe:2.3:a:haxx:curl:7.4.1
-
cpe:2.3:a:haxx:curl:7.4.2
-
cpe:2.3:a:haxx:curl:7.40.0
-
cpe:2.3:a:haxx:curl:7.41.0
-
cpe:2.3:a:haxx:curl:7.42.0
-
cpe:2.3:a:haxx:curl:7.42.1
-
cpe:2.3:a:haxx:curl:7.43.0
-
cpe:2.3:a:haxx:curl:7.44.0
-
cpe:2.3:a:haxx:curl:7.45.0
-
cpe:2.3:a:haxx:curl:7.46.0
-
cpe:2.3:a:haxx:curl:7.47.0
-
cpe:2.3:a:haxx:curl:7.47.1
-
cpe:2.3:a:haxx:curl:7.48.0
-
cpe:2.3:a:haxx:curl:7.49.0
-
cpe:2.3:a:haxx:curl:7.49.1
-
-
cpe:2.3:a:haxx:curl:7.5.1
-
cpe:2.3:a:haxx:curl:7.5.2
-
cpe:2.3:a:haxx:curl:7.50.0
-
cpe:2.3:a:haxx:curl:7.50.1
-
cpe:2.3:a:haxx:curl:7.50.2
-
cpe:2.3:a:haxx:curl:7.50.3
-
cpe:2.3:a:haxx:curl:7.51.0
-
cpe:2.3:a:haxx:curl:7.52.0
-
cpe:2.3:a:haxx:curl:7.52.1
-
cpe:2.3:a:haxx:curl:7.53.0
-
cpe:2.3:a:haxx:curl:7.53.1
-
cpe:2.3:a:haxx:curl:7.54.0
-
cpe:2.3:a:haxx:curl:7.54.1
-
cpe:2.3:a:haxx:curl:7.55.0
-
cpe:2.3:a:haxx:curl:7.55.1
-
cpe:2.3:a:haxx:curl:7.56.0
-
cpe:2.3:a:haxx:curl:7.56.1
-
cpe:2.3:a:haxx:curl:7.57.0
-
cpe:2.3:a:haxx:curl:7.58.0
-
cpe:2.3:a:haxx:curl:7.59.0
-
-
cpe:2.3:a:haxx:curl:7.6.1
-
cpe:2.3:a:haxx:curl:7.60.0
-
cpe:2.3:a:haxx:curl:7.61.0
-
cpe:2.3:a:haxx:curl:7.61.1
-
cpe:2.3:a:haxx:curl:7.62.0
-
cpe:2.3:a:haxx:curl:7.63.0
-
cpe:2.3:a:haxx:curl:7.64.0
-
cpe:2.3:a:haxx:curl:7.64.1
-
cpe:2.3:a:haxx:curl:7.65.0
-
cpe:2.3:a:haxx:curl:7.65.1
-
cpe:2.3:a:haxx:curl:7.65.2
-
cpe:2.3:a:haxx:curl:7.65.3
-
cpe:2.3:a:haxx:curl:7.66.0
-
cpe:2.3:a:haxx:curl:7.67.0
-
cpe:2.3:a:haxx:curl:7.68.0
-
cpe:2.3:a:haxx:curl:7.69.0
-
cpe:2.3:a:haxx:curl:7.69.1
-
-
cpe:2.3:a:haxx:curl:7.7.1
-
cpe:2.3:a:haxx:curl:7.7.2
-
cpe:2.3:a:haxx:curl:7.7.3
-
cpe:2.3:a:haxx:curl:7.70.0
-
cpe:2.3:a:haxx:curl:7.71.0
-
cpe:2.3:a:haxx:curl:7.71.1
-
cpe:2.3:a:haxx:curl:7.72.0
-
cpe:2.3:a:haxx:curl:7.73.0
-
-
cpe:2.3:a:haxx:curl:7.8.1
-
-
cpe:2.3:a:haxx:curl:7.9.1
-
cpe:2.3:a:haxx:curl:7.9.2
-
cpe:2.3:a:haxx:curl:7.9.3
-
cpe:2.3:a:haxx:curl:7.9.4
-
cpe:2.3:a:haxx:curl:7.9.5
-
cpe:2.3:a:haxx:curl:7.9.6
-
cpe:2.3:a:haxx:curl:7.9.7
-
cpe:2.3:a:haxx:curl:7.9.8
-
cpe:2.3:a:netapp:clustered_data_ontap:-
-
cpe:2.3:a:netapp:hci_management_node:-
-
cpe:2.3:a:netapp:solidfire:-
-
cpe:2.3:a:oracle:communications_billing_and_revenue_management:12.0.0.3.0
-
cpe:2.3:a:oracle:communications_cloud_native_core_policy:1.14.0
-
cpe:2.3:a:oracle:essbase:21.2
-
cpe:2.3:a:oracle:peoplesoft_enterprise_peopletools:8.58
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:-
-
cpe:2.3:a:siemens:sinec_infrastructure_network_services:1.0.1
-
cpe:2.3:a:splunk:universal_forwarder:8.2.0
-
cpe:2.3:a:splunk:universal_forwarder:8.2.10
-
cpe:2.3:a:splunk:universal_forwarder:8.2.11
-
cpe:2.3:a:splunk:universal_forwarder:8.2.6
-
cpe:2.3:a:splunk:universal_forwarder:8.2.7
-
cpe:2.3:a:splunk:universal_forwarder:8.2.8
-
cpe:2.3:a:splunk:universal_forwarder:8.2.9
-
cpe:2.3:a:splunk:universal_forwarder:9.0.0
-
cpe:2.3:a:splunk:universal_forwarder:9.0.1
-
cpe:2.3:a:splunk:universal_forwarder:9.0.2
-
cpe:2.3:a:splunk:universal_forwarder:9.0.3
-
cpe:2.3:a:splunk:universal_forwarder:9.0.4
-
cpe:2.3:a:splunk:universal_forwarder:9.0.5
-
cpe:2.3:a:splunk:universal_forwarder:9.1.0
-
cpe:2.3:h:fujitsu:m10-1:-
-
cpe:2.3:h:fujitsu:m10-4:-
-
cpe:2.3:h:fujitsu:m10-4s:-
-
cpe:2.3:h:fujitsu:m12-1:-
-
cpe:2.3:h:fujitsu:m12-2:-
-
cpe:2.3:h:fujitsu:m12-2s:-
-
cpe:2.3:h:netapp:hci_compute_node:-
-
cpe:2.3:h:netapp:hci_storage_node:-
-
cpe:2.3:o:apple:mac_os_x:10.14.0
-
cpe:2.3:o:apple:mac_os_x:10.14.1
-
cpe:2.3:o:apple:mac_os_x:10.14.2
-
cpe:2.3:o:apple:mac_os_x:10.14.3
-
cpe:2.3:o:apple:mac_os_x:10.14.4
-
cpe:2.3:o:apple:mac_os_x:10.14.5
-
cpe:2.3:o:apple:mac_os_x:10.14.6
-
cpe:2.3:o:apple:mac_os_x:10.15
-
cpe:2.3:o:apple:mac_os_x:10.15.1
-
cpe:2.3:o:apple:mac_os_x:10.15.2
-
cpe:2.3:o:apple:mac_os_x:10.15.3
-
cpe:2.3:o:apple:mac_os_x:10.15.4
-
cpe:2.3:o:apple:mac_os_x:10.15.5
-
cpe:2.3:o:apple:mac_os_x:10.15.6
-
cpe:2.3:o:apple:mac_os_x:10.15.7
-
cpe:2.3:o:apple:macos:11.0.1
-
cpe:2.3:o:apple:macos:11.1
-
cpe:2.3:o:apple:macos:11.2
-
cpe:2.3:o:debian:debian_linux:10.0
-
cpe:2.3:o:debian:debian_linux:9.0
-
cpe:2.3:o:fedoraproject:fedora:32
-
cpe:2.3:o:fedoraproject:fedora:33
-
cpe:2.3:o:fujitsu:m10-1_firmware:-
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp2280
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m10-1_firmware:xcp3100
-
cpe:2.3:o:fujitsu:m10-4_firmware:-
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp2280
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m10-4_firmware:xcp3100
-
cpe:2.3:o:fujitsu:m10-4s_firmware:-
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp2280
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m10-4s_firmware:xcp3100
-
cpe:2.3:o:fujitsu:m12-1_firmware:-
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp3090
-
cpe:2.3:o:fujitsu:m12-1_firmware:xcp3100
-
cpe:2.3:o:fujitsu:m12-2_firmware:-
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp3090
-
cpe:2.3:o:fujitsu:m12-2_firmware:xcp3100
-
cpe:2.3:o:fujitsu:m12-2s_firmware:-
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp2361
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp2400
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp2410
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp3070
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp3090
-
cpe:2.3:o:fujitsu:m12-2s_firmware:xcp3100
-
cpe:2.3:o:netapp:hci_bootstrap_os:-