CVE-2020-37139

8.4

Odin · Secure FTP Expert

Odin Secure FTP Expert 7.6.3 is vulnerable to a local buffer overflow caused by oversized input in connection fields, allowing an attacker to crash the application.

Executive summary

A local denial of service vulnerability in Odin Secure FTP Expert 7.6.3 allows an unauthenticated attacker to crash the application via buffer overflow.

Vulnerability

The application fails to properly limit the allocation of resources when processing site information fields, allowing an unauthenticated local user to trigger a buffer overflow by inputting 108 characters into connection fields. This flaw, classified under CWE-770, results in an immediate application crash.

Business impact

The exploitation of this vulnerability results in the disruption of file transfer services, leading to potential operational downtime for users relying on the software for data movement. While the CVSS score of 8.4 suggests a high severity, the impact is strictly limited to a local denial of service, meaning the business risk is primarily centered on availability and process continuity rather than data exfiltration or unauthorized system access.

Remediation

Immediate Action: There is no vendor-supplied patch for this legacy software; users should discontinue use of Odin Secure FTP Expert 7.6.3 and migrate to a modern, actively maintained FTP client.

Proactive Monitoring: Security teams should monitor workstation and server logs for abnormal application termination events or unexpected process crashes associated with the FTP client.

Compensating Controls: Ensure that workstations are configured with strict local access controls to prevent unauthorized users from interacting with the application interface.

Exploitation status

Public Exploit Available: Yes, a proof-of-concept exists as documented in the Exploit Database (EDB-ID: 48262).

Analyst recommendation

Given that Odin Secure FTP Expert 7.6.3 is no longer supported and lacks a security patch, the risk of continued use is significant. Organizations should audit their environments to identify any remaining installations of this software and prioritize the migration to a secure, supported alternative to eliminate this denial of service risk entirely.

Sources

Originally found and disclosed by Ivan Marmolejo, per the CVE Program record.