CVE-2022-29620
Published Jun 7, 2022
·Updated
** DISPUTED ** FileZilla v3.59.0 allows attackers to obtain cleartext passwords of connected SSH or FTP servers via a memory dump.- NOTE: the vendor does not consider this a vulnerability.
Affected Software
1 affected component
Filezilla-project Filezilla Client=3.59.0
Event History
Jun 7, 2022
CVE Published
via MITRE·08:07 PM
Data Sourced
via MITRE·08:07 PM
Description
Disputed
09:15 PM
Frequently Asked Questions
1
What is the severity of CVE-2022-29620?
CVE-2022-29620 has been disputed by the vendor and is not officially classified as a vulnerability.
2
How do I fix CVE-2022-29620?
Since the vendor does not acknowledge CVE-2022-29620 as a vulnerability, there are currently no official fixes or mitigations available.
3
What impact does CVE-2022-29620 have on FileZilla 3.59.0?
CVE-2022-29620 allows attackers to extract cleartext passwords of SSH or FTP servers through memory dumps.
4
What versions of FileZilla are affected by CVE-2022-29620?
CVE-2022-29620 specifically affects FileZilla Client version 3.59.0.
5
Is there a recommended action for users of FileZilla 3.59.0 regarding CVE-2022-29620?
Users of FileZilla 3.59.0 should remain cautious and consider upgrading to newer versions if available.