peter bassill · operator
$ cve CVE-2020-12651 JSON

CVE-2020-12651

9.8
CRITICAL · CVSS 3.1 · EPSS 6.6% (pctl 94)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.

Scoring

CVSS9.8 (CRITICAL, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS6.6% — more likely to be exploited than 94% of all CVEs
WeaknessCWE-190
On CISA KEVno
Public exploitnone known
Published2020-05-15
Last modified2026-06-17

Affected (5)

VendorProduct
appleiphone os
applemacos
linuxlinux kernel
microsoftwindows
vandykesecurecrt

References

→ the Explorer  ·  watch your stack  ·  NVD