CVE-2020-8815

HIGH

BearFTP < 0.3.1 - Denial of Service via Slowloris Packet Flood

Title source: llm
STIX 2.1

Description

Improper connection handling in the base connection handler in IKTeam BearFTP before v0.3.1 allows a remote attacker to achieve denial of service via a Slowloris approach by sending a large volume of small packets.

Scores

CVSS v3 7.5
EPSS 0.0219
EPSS Percentile 80.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Details

CWE
CWE-20
Status published
Products (1)
iktm/bearftp < 0.3.1
Published Feb 12, 2020
Tracked Since Feb 18, 2026