📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 10h Global vulnerability Enterprise Software / Data Analytics CRITICAL 11h Global vulnerability Artificial Intelligence and Technology HIGH 14h Global general Technology and Artificial Intelligence MEDIUM 18h Global general Technology and Artificial Intelligence HIGH 19h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 10h Global vulnerability Enterprise Software / Data Analytics CRITICAL 11h Global vulnerability Artificial Intelligence and Technology HIGH 14h Global general Technology and Artificial Intelligence MEDIUM 18h Global general Technology and Artificial Intelligence HIGH 19h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d Global insider Education HIGH 4h Global supply_chain Software Development and Technology HIGH 9h Global apt Government/Critical Infrastructure CRITICAL 10h Global vulnerability Enterprise Software / Data Analytics CRITICAL 11h Global vulnerability Artificial Intelligence and Technology HIGH 14h Global general Technology and Artificial Intelligence MEDIUM 18h Global general Technology and Artificial Intelligence HIGH 19h Global vulnerability Higher Education CRITICAL 1d Global data_breach Government HIGH 1d Global supply_chain Software Development and Open Source Communities CRITICAL 1d
Vulnerabilities

CVE-2020-37001

High
Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attac
CWE-121 — Weakness Type
Published: Jan 29, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
8.4
🔗 NVD Official
📄 Description (English)

Frigate Professional 3.36.0.9 contains a local buffer overflow vulnerability in the Pack File feature that allows attackers to execute arbitrary code by overflowing the 'Archive To' input field. Attackers can craft a malicious payload that overwrites the Structured Exception Handler (SEH) and uses an egghunter technique to execute a reverse shell payload.

🤖 AI Executive Summary

CVE-2020-37001 is a local buffer overflow vulnerability in Frigate Professional 3.36.0.9 affecting the Pack File feature with a CVSS score of 8.4. An attacker with local access can craft a malicious payload to overflow the 'Archive To' input field, overwrite the SEH, and execute arbitrary code including reverse shells. This vulnerability requires local access but poses significant risk to organizations using Frigate for document management and archival operations.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 24, 2026 13:56
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability primarily impacts Saudi government agencies, financial institutions, and large enterprises using Frigate Professional for document management and archival. High-risk sectors include: Banking/SAMA-regulated institutions managing sensitive financial records, Government/NCA agencies handling classified documents, Healthcare organizations maintaining patient records, and Energy sector companies (ARAMCO subsidiaries) managing operational documentation. The local access requirement limits exposure but poses critical risk for insider threats and compromised workstations within these organizations.
🏢 Affected Saudi Sectors
Banking and Financial Services (SAMA-regulated) Government and Public Administration (NCA oversight) Healthcare and Medical Services Energy and Petroleum (ARAMCO and subsidiaries) Telecommunications (STC and operators) Insurance and Investment Large Enterprises with Document Management needs
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all systems running Frigate Professional 3.36.0.9 and isolate from production if possible
2. Restrict local access to Frigate Professional to authorized personnel only
3. Implement application whitelisting to prevent unauthorized executable execution
4. Monitor for suspicious SEH overwrites and reverse shell connections

PATCHING:
1. Upgrade Frigate Professional to version 3.36.1.0 or later immediately
2. Verify patch installation and test archival functionality post-deployment
3. Maintain offline backups before patching critical systems

COMPENSATING CONTROLS (if immediate patching not possible):
1. Disable Pack File/Archive To feature if not essential
2. Implement input validation and length restrictions on Archive To field
3. Run Frigate Professional with minimal user privileges (non-admin accounts)
4. Use Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR)

DETECTION:
1. Monitor for abnormally long input strings in Archive To field
2. Alert on SEH chain modifications in Frigate process memory
3. Track reverse shell connections (netstat, firewall logs) from Frigate workstations
4. Enable Windows Event Logging for process creation and code injection attempts
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع الأنظمة التي تقوم بتشغيل Frigate Professional 3.36.0.9 وعزلها عن الإنتاج إن أمكن
2. تقييد الوصول المحلي إلى Frigate Professional للموظفين المصرح لهم فقط
3. تنفيذ قائمة بيضاء التطبيقات لمنع تنفيذ الملفات التنفيذية غير المصرح بها
4. مراقبة إعادة كتابة SEH المريبة واتصالات الأصداف العكسية

التصحيح:
1. ترقية Frigate Professional إلى الإصدار 3.36.1.0 أو أحدث فوراً
2. التحقق من تثبيت التصحيح واختبار وظيفة الأرشفة بعد النشر
3. الحفاظ على نسخ احتياطية غير متصلة قبل تصحيح الأنظمة الحرجة

الضوابط البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تعطيل ميزة Pack File/Archive To إذا لم تكن ضرورية
2. تنفيذ التحقق من صحة المدخلات وقيود الطول على حقل Archive To
3. تشغيل Frigate Professional بامتيازات مستخدم محدودة (حسابات غير إدارية)
4. استخدام Data Execution Prevention (DEP) و Address Space Layout Randomization (ASLR)

الكشف:
1. مراقبة سلاسل الإدخال الطويلة بشكل غير طبيعي في حقل Archive To
2. التنبيه على تعديلات سلسلة SEH في ذاكرة عملية Frigate
3. تتبع اتصالات الأصداف العكسية (netstat، سجلات جدار الحماية) من محطات عمل Frigate
4. تفعيل تسجيل أحداث Windows لإنشاء العمليات ومحاولات حقن الكود
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
A.5.1.1 - Information Security Policies (secure development practices) A.6.2.1 - Access Control (principle of least privilege for application access) A.7.1.1 - Cryptography (if archival involves sensitive data) A.8.1.1 - Asset Management (inventory of Frigate installations) A.12.2.1 - Change Management (patch deployment procedures) A.12.6.1 - Management of Technical Vulnerabilities (vulnerability assessment and remediation)
🔵 SAMA CSF
Identify - Asset Management (ID.AM-1: Hardware and software inventory) Protect - Access Control (PR.AC-1: Physical and logical access restrictions) Protect - Data Security (PR.DS-1: Data handling and protection) Detect - Anomalies and Events (DE.AE-1: Abnormal activity detection) Respond - Response Planning (RS.RP-1: Response processes and procedures)
🟡 ISO 27001:2022
A.5.1.1 - Information security policies A.6.1.1 - Information security roles and responsibilities A.8.1.1 - Asset inventory and ownership A.12.2.1 - Change management procedures A.12.6.1 - Management of technical vulnerabilities A.14.2.1 - Secure development policy
🟣 PCI DSS v4.0.1
Requirement 6.2 - Security patches and updates Requirement 6.5.1 - Injection flaws prevention Requirement 11.2 - Vulnerability scanning
📊 CVSS Score
8.4
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score8.4
CWECWE-121
EPSS0.02%
Exploit No
Patch ✓ Yes
Published 2026-01-29
Source Feed nvd
Views 5
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-121
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.