CVE-2017-15272: Psftp Psftpd
Medium severity, CVSS 5.3. EPSS: 0.6% chance of exploitation in the next 30 days.
The PSFTPd 10.0.4 Build 729 server stores its configuration inside PSFTPd.dat. This file is a Microsoft Access Database and can be extracted. The application sets the encrypt flag with the password "ITsILLEGAL"; however, this password is not required to extract the data. Cleartext is used for a user password.
Affected products
- Psftp Psftpd: version 10.0.4 only
Published 2017-11-15. Last modified 2026-06-17.