CVE-2020-37001: FRIGATE3 Frigate Professional
High severity, CVSS 8.4. EPSS: 0.2% chance of exploitation in the next 30 days.
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.
Affected products
- FRIGATE3 Frigate Professional: version 3.36.0.9 only
Published 2026-01-29. Last modified 2026-06-17.