ProFTPD Official Websiteproduct
http://www.proftpd.org/ CVE-2021-47865
HIGH
ProFTPD 1.3.7a - Remote Denial of Service
Record summary
CVE-2021-47865 has a selected CVSS score of 8.7 (high); EIP currently links 1 catalogued exploit.
Description
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
CISA SSVC decision
ExploitationPoC
AutomatableYes
Technical impactPartial
CISA Coordinator · SSVC 2.0.3 · Evaluated Jan 22, 2026 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
ProFTPDBrowse ProFTPD / ProFTPDDefault status: unaffected | CVE List | 1.3.7a | affected |
Proofs of concept
1Catalogued exploits
ExploitDBProFTPD 1.3.7a - Remote Denial of ServiceExploitDB exploitby xynmapsNot analyzed1 file
References
6github.com
https://github.com/proftpd/proftpd ProFTPD GitHub Repositoryissue tracking
https://github.com/proftpd/proftpd/issues/1298 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-47865 ExploitDB-49697exploit
https://www.exploit-db.com/exploits/49697 VulnCheck Advisory: ProFTPD 1.3.7a - Remote Denial of ServiceThird-party advisory
https://www.vulncheck.com/advisories/proftpd-a-remote-denial-of-service