CVE-2020-11940: Ntop Ndpi

High severity, CVSS 7.5. EPSS: 1.3% chance of exploitation in the next 30 days.

In nDPI through 3.2 Stable, an out-of-bounds read in concat_hash_string in ssh.c can be exploited by a network-positioned attacker that can send malformed SSH protocol messages on a network segment monitored by nDPI's library.

Affected products

  • Ntop Ndpi: up to and including 3.2

Published 2020-04-23. Last modified 2026-06-17.