← Vulnerability feed

Vulnerability record · CVE-2020-36880 · published 5 December 2025

CVE-2020-36880: Flexense diskboss memory buffer overflow vulnerability

Flexense · Diskboss

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system.

8.6 CVSS 4.0 High EPSS 0.24% · top 86.9% CWE-119 · Memory buffer overflow
8.6CVSS 4.0 base score
0.24%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
3References, 1 tagged exploit
17 Jun 2026Last modified by NVD

Description

Flexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Reports and Data Directory' field that allows an attacker to execute arbitrary code on the system.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-36880 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2018-5262Flexense diskboss out-of-bounds write vulnerabilityA stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in the contex…EPSS 39%8.7CVE-2020-36882Flexense diskboss unrestricted file upload vulnerabilityFlexsense DiskBoss 7.7.14 allows unauthenticated attackers to upload arbitrary files via /Command/Search Files/Directory field, leading to a denial o…EPSS 0.62%8.6CVE-2020-36881Flexense diskboss memory buffer overflow vulnerabilityFlexsense DiskBoss 7.7.14 contains a local buffer overflow vulnerability in the 'Input Directory' component that allows unauthenticated attackers to …EPSS 0.37%8.1CVE-2018-5261Flexense diskboss missing encryption vulnerabilityAn issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for the encryp…EPSS 0.46%7.8CVE-2017-7310Flexense disk tools XML import buffer overflow allows code executionA buffer overflow in the Import Command of multiple Flexense products (SyncBreeze, DiskSorter, DiskBoss, DiskPulse, DiskSavvy, DupScout, VX Search) b…EPSS 54%analysed7.5CVE-2017-15665Flexense diskboss vulnerabilityIn Flexense DiskBoss Enterprise 8.5.12, the Control Protocol suffers from a denial of service vulnerability. The attack vector is a crafted SERVER_GE…EPSS 9.1%6.1CVE-2018-10294Flexense diskboss cross-site scripting vulnerabilityFlexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.EPSS 0.69%9.5CVE-2026-88772Citrix NetScaler Improper Restriction of Operations within the Bounds of a Memory Buffer VulnerabilityVulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 F…KEV

Source: NIST National Vulnerability Database (record CVE-2020-36880), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.