CVE-1999-1515

TenFour TFS Gateway 4.0 - Denial of Service via Malformed Message Handling

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-1999-1515. PoCs published by anonymous.

AI-analyzed exploit summary This exploit demonstrates a denial of service vulnerability in TFS Gateway 4.0 by sending a malformed email that triggers repeated failed delivery attempts, consuming system resources. The PoC uses SMTP commands to send an email with invalid sender and recipient addresses.

Description

A non-default configuration in TenFour TFS Gateway 4.0 allows an attacker to cause a denial of service via messages with incorrect sender and recipient addresses, which causes the gateway to continuously try to return the message every 10 seconds.

Exploits (1)

exploitdb WORKING POC VERIFIED
by anonymous · textdoshardware
https://www.exploit-db.com/exploits/19477

This exploit demonstrates a denial of service vulnerability in TFS Gateway 4.0 by sending a malformed email that triggers repeated failed delivery attempts, consuming system resources. The PoC uses SMTP commands to send an email with invalid sender and recipient addresses.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Trivial
Reliability
Reliable
Target: TFS Gateway 4.0
No auth needed
Prerequisites: TFS Gateway 4.0 configured with 'return entire message to sender' enabled for failed send attempts · Network access to the SMTP port of the target
mistral-large-3 · analyzed Feb 16, 2026 Full analysis →

References (2)

Core 2
Core References
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/613
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/3290

Scores

EPSS 0.0464
EPSS Percentile 90.8%

Details

Status published
Products (1)
tenfour/tfs_gateway 4.0
Published Aug 31, 1999
Tracked Since Feb 18, 2026