CVE-2020-12651: Vandyke Securecrt

Critical severity, CVSS 9.8. EPSS: 6.6% chance of exploitation in the next 30 days.

SecureCRT before 8.7.2 allows remote attackers to execute arbitrary code via an Integer Overflow and a Buffer Overflow because a banner can trigger a line number to CSI functions that exceeds INT_MAX.

Affected products

  • Vandyke Securecrt: before 8.7.2 (fixed in 8.7.2); before 2.4 (fixed in 2.4)

Published 2020-05-15. Last modified 2026-06-17.