PT-2026-3817 · Proftpd+1 · Proftpd+1

Xynmaps

·

Published

2026-01-21

·

Updated

2026-01-21

·

CVE-2021-47865

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ProFTPD version 1.3.7a
Description A denial of service issue allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. By repeatedly establishing connections using threading, attackers can exhaust server connection limits and block legitimate user access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Weakness Enumeration

Related Identifiers

CVE-2021-47865

Affected Products

Proftpd
Proftpd-Dfsg