QID 377614

Date Published: 2022-10-06

QID 377614: Filezilla Server Information Disclosure Vulnerability (CVE-2014-0224)

FileZilla is an FTP program for file uploading and downloading to and from your FTP site, server, or host.

CVE-2014--0224: OpenSSL does not properly restrict processing of ChangeCipherSpec messages, which allows man-in-the-middle attackers to hijack sessions or obtain sensitive information, via a crafted TLS handshake, also known as the "CCS Injection" vulnerability. Affected versions

Filezilla server prior to 0.9.45

QID detection logic
It checks for the vulnerable version from the file FileZilla Server.exe

It may impact the confidentiality and integrity.

  • CVSS V3 rated as High - 7.4 severity.
  • CVSS V2 rated as Medium - 5.8 severity.
  • Solution
    Customers are advised to check for Filezilla 0.9.45 (2014-06-07) for more details
    Vendor References

    CVEs related to QID 377614

    Software Advisories
    Advisory ID Software Component Link
    0.9.45 (2014-06-07) URL Logo filezilla-project.org/versions.php?type=server