← Vulnerability feed

Vulnerability record · CVE-2022-32073 · published 13 July 2022

CVE-2022-32073: Wolfssh integer overflow vulnerability

WWolfssh · Wolfssh

WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

9.8 CVSS 3.1 Critical EPSS 1.9% · top 20.8% CWE-190 · Integer overflow
9.8CVSS 3.1 base score, v2 7.5
1.9%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

WolfSSH v1.4.7 was discovered to contain an integer overflow via the function wolfSSH_SFTP_RecvRMDIR.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://github.com/wolfSSL/wolfssh/pull/360 PatchThird Party Advisory
https://github.com/wolfSSL/wolfssh/pull/360 PatchThird Party Advisory

Track CVE-2022-32073 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.4CVE-2025-14942Wolfssh improper authentication vulnerabilitywolfSSH’s key exchange state machine can be manipulated to leak the client’s password in the clear, trick the client to send a bogus signature, or tr…EPSS 0.40%9.4CVE-2025-11625Wolfssh improper authentication vulnerabilityImproper host authentication vulnerability in wolfSSH version 1.4.20 and earlier clients that allows authentication bypass and leaking of clients cre…EPSS 0.43%9.1CVE-2024-2873Wolfssh improper authentication vulnerabilityA vulnerability was found in wolfSSH's server-side state machine before versions 1.4.17. A malicious client could create channels without first perfo…EPSS 0.62%5.1CVE-2025-15382Wolfssh out-of-bounds read vulnerabilityA heap buffer over-read vulnerability exists in the wolfSSH_CleanPath() function in wolfSSH. An authenticated remote attacker can trigger the issue v…EPSS 0.34%2.3CVE-2026-0930Wolfssh out-of-bounds read vulnerabilityPotential read out of bounds case with wolfSSHd on Windows while handling a terminal resize request. An authenticated user could trigger the out of b…EPSS 0.17%1.8CVE-2025-11624Wolfssh out-of-bounds write vulnerabilityPotential stack buffer overwrite on the SFTP server side when receiving a malicious packet that has a handle size larger than the system handle or fi…EPSS 0.37%8.4CVE-2025-48595Android Framework integer overflow enables local code executionAn integer overflow in multiple locations of the Android Framework can be turned into code execution. It allows a local attacker to escalate privileg…KEVEPSS 1.7%analysed7.8CVE-2021-30952Apple WebKit integer overflow allows code execution via crafted web contentAn integer overflow in Apple's WebKit engine was fixed by improved input validation across tvOS 15.2, macOS Monterey 12.1, Safari 15.2, iOS/iPadOS 15…KEVEPSS 7.0%analysed

Source: NIST National Vulnerability Database (record CVE-2022-32073), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.