Vulnerability record · CVE-2015-7602 · published 29 September 2015
CVE-2015-7602: BisonFTP 3.5 directory traversal in RETR command
BBisonware · Bisonftp
BisonWare BisonFTP 3.5 fails to sanitize the path supplied in a RETR command, allowing a ../ sequence to escape the FTP root. An attacker can then read arbitrary files on the host, exposing configuration, credential and system files. The flaw is a classic CWE-22 path traversal in an FTP service.
Description
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command.
AV:N/AC:L/Au:N/C:C/I:N/A:N
Automated analysis
high priorityUnauthenticated remote arbitrary file read with public exploit code and very high EPSS, though no KEV listing or confirmed in-the-wild use is recorded.
What it is
BisonWare BisonFTP 3.5 fails to sanitize the path supplied in a RETR command, allowing a ../ sequence to escape the FTP root. An attacker can then read arbitrary files on the host, exposing configuration, credential and system files. The flaw is a classic CWE-22 path traversal in an FTP service.
Impact
An attacker gains read access to any file the FTP service account can reach, which can leak credentials, configuration and OS files. There is no integrity or availability impact per the CVSS vector; the loss is confidentiality only.
Attack surface
Reachable over the network on the FTP service port; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. The attacker only needs to issue a crafted RETR command containing ../.
Exploitation
Public exploit code exists, referenced by Packet Storm and Exploit-DB entries, and EPSS is 0.61542 (99th percentile), indicating high predicted exploitation activity. The CVE is not listed in CISA KEV, so no confirmed in-the-wild use is recorded here.
What to do
- Upgrade or replace BisonFTP 3.5; the record names no fixed version, so confirm vendor status before relying on a patch.
- If the product cannot be updated, restrict FTP access to trusted networks and disable anonymous or unauthenticated access.
- Run the FTP service under a low-privilege account with access limited to the intended file root.
- Place the service behind a proxy or firewall rule that blocks or inspects RETR paths containing traversal sequences.
- Retire the FTP service in favor of a maintained, supported file transfer product.
Detection
- Monitor FTP logs for RETR commands containing ../ or encoded traversal sequences.
- Alert on FTP sessions reading files outside the configured root, such as /etc/passwd or application config files.
- Baseline normal RETR file paths per account and flag deviations.
- Correlate FTP access from unexpected source IPs with subsequent file-read or credential-access activity.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2015-7602 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2015-7602), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.