CVE-2001-0405

Linux Kernel - Firewall Bypass via FTP PORT Command

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2001-0405. PoCs published by Cristiano Lincoln Mattos.

AI-analyzed exploit summary This exploit leverages a vulnerability in the Linux iptables FTP stateful inspection module (CVE-2001-0405) to manipulate the connection table. By sending a crafted PORT command with an arbitrary IP and port, it tricks the firewall into allowing unauthorized connections from the FTP server to the specified target.

Description

ip_conntrack_ftp in the IPTables firewall for Linux 2.4 allows remote attackers to bypass access restrictions for an FTP server via a PORT command that lists an arbitrary IP address and port number, which is added to the RELATED table and allowed by the firewall.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Cristiano Lincoln Mattos · perlremotelinux
https://www.exploit-db.com/exploits/20765

This exploit leverages a vulnerability in the Linux iptables FTP stateful inspection module (CVE-2001-0405) to manipulate the connection table. By sending a crafted PORT command with an arbitrary IP and port, it tricks the firewall into allowing unauthorized connections from the FTP server to the specified target.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Trivial
Reliability
Reliable
Target: Linux kernel iptables (FTP connection tracking module)
No auth needed
Prerequisites: Access to an FTP server behind the vulnerable iptables firewall · Network connectivity to the FTP server
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (6)

Core 6
Core References
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-084.html
Exploit, Patch, Vendor Advisory mailing-list x_refsource_bugtraq
http://archives.neohapsis.com/archives/bugtraq/2001-04/0271.html
Vendor Advisory vendor-advisory x_refsource_redhat
http://www.redhat.com/support/errata/RHSA-2001-052.html
Exploit, Patch, Vendor Advisory vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/2602
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/6390
Various Sources vendor-advisory x_refsource_mandrake
http://www.linux-mandrake.com/en/security/2001/MDKSA-2001-071.php3

Scores

EPSS 0.1025
EPSS Percentile 95.1%

Details

Status published
Products (4)
linux/linux_kernel 2.4.0 (2 CPE variants)
linux/linux_kernel 2.4.1
linux/linux_kernel 2.4.2
linux/linux_kernel 2.4.3
Published Jul 02, 2001
Tracked Since Feb 18, 2026