Buffer overflow in NetWin SurgeFTP before 23d2 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a long string within the authentication request.
Conclusion & alert: CVE-2013-4742 is rated Moderate Risk (61.9/100): CVSS High severity, with medium exploitation likelihood (EPSS 4.21%). Mandatory action: Review affected assets and schedule remediation.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-06-15 | 3.71% | 4.21% | +0.50% |
| 2 | 2025-09-29 | 4.16% | 3.71% | -0.45% |
| 3 | 2025-03-30 | — | 4.16% | — |
Full EPSS history (9 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 7.5 | 2.0 | HIGH |
|
10.0 | 6.4 | [email protected] |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| netwin | surgeftp | <= 2.3b1 | cpe:2.3:a:netwin:surgeftp:*:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.0c | cpe:2.3:a:netwin:surgeftp:2.0c:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.0d | cpe:2.3:a:netwin:surgeftp:2.0d:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.0e | cpe:2.3:a:netwin:surgeftp:2.0e:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.0f | cpe:2.3:a:netwin:surgeftp:2.0f:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.2k1 | cpe:2.3:a:netwin:surgeftp:2.2k1:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.2k3 | cpe:2.3:a:netwin:surgeftp:2.2k3:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.2m1 | cpe:2.3:a:netwin:surgeftp:2.2m1:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a1 | cpe:2.3:a:netwin:surgeftp:2.3a1:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a2 | cpe:2.3:a:netwin:surgeftp:2.3a2:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a6 | cpe:2.3:a:netwin:surgeftp:2.3a6:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a7 | cpe:2.3:a:netwin:surgeftp:2.3a7:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a8 | cpe:2.3:a:netwin:surgeftp:2.3a8:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a9 | cpe:2.3:a:netwin:surgeftp:2.3a9:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a10 | cpe:2.3:a:netwin:surgeftp:2.3a10:*:*:*:*:*:*:* |
| netwin | surgeftp | 2.3a12 | cpe:2.3:a:netwin:surgeftp:2.3a12:*:*:*:*:*:*:* |