CVE-2018-7449
HIGHSEGGER embOS/IP FTP Server < 3.22a - Denial of Service via Invalid LIST STOR or RETR Command
Title source: llmExploitation Summary
EIP tracks 2 public exploits for CVE-2018-7449. PoCs published by hyp3rlinx, antogit-sys.
AI-analyzed exploit summary This exploit demonstrates a denial-of-service vulnerability in SEGGER embOS/IP FTP Server v3.22 by sending malformed FTP commands (e.g., STOR, LIST, RETR) that crash the server. The PoC connects to the FTP server, authenticates anonymously, and sends a crafted STOR command to trigger the crash.
Description
SEGGER FTP Server for Windows before 3.22a allows remote attackers to cause a denial of service (daemon crash) via an invalid LIST, STOR, or RETR command.
Exploits (2)
This exploit demonstrates a denial-of-service vulnerability in SEGGER embOS/IP FTP Server v3.22 by sending malformed FTP commands (e.g., STOR, LIST, RETR) that crash the server. The PoC connects to the FTP server, authenticates anonymously, and sends a crafted STOR command to trigger the crash.
This PoC exploits CVE-2018-7449, a DoS vulnerability in SEGGER embOS/IP FTP Server 3.22, by sending malformed FTP commands (STOR, LIST, RETR) to crash the daemon. It requires valid FTP credentials and targets the specific server version.
References (2)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H