Record summary

CVE-2021-30047 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

CISA SSVC decision

ExploitationPoC
AutomatableYes
Technical impactPartial

CISA Coordinator · SSVC 2.0.3 · Evaluated Oct 3, 2024 · Source: CVE List

Proofs of concept

1

Catalogued exploits

ExploitDBvsftpd 3.0.3 - Remote Denial of ServiceExploitDB exploitby xynmapsNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHvsftpd < 3.0.3 - DoSCVSS 7.5

vsftpd before 3.0.3 allows remote attackers to cause a denial of service by sending a crafted FTP command.

Impact

Attackers can send crafted FTP commands to crash the vsftpd daemon, causing denial of service and interrupting FTP services for legitimate users.

Remediation

Upgrade to vsftpd version 3.0.3 or later that addresses the denial of service vulnerability.

Authorspussycat0x
Template tagscvecve2021networkftpvsftpdtcppassivevuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CPE: cpe:2.3:a:vsftpd_project:vsftpd:3.0.3:*:*:*:*:*:*:*
Shodan: vsftpd
Shodan: product:"vsftpd"

Source: ProjectDiscovery

References

2