PT-2026-3817 · Proftpd+1 · Proftpd+1

·

CVE-2021-47865

·

Published

2026-01-21

·

Updated

2026-01-21

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions ProFTPD version 1.3.7a
Description A denial of service issue allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. By repeatedly establishing connections using threading, attackers can exhaust server connection limits and block legitimate user access.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Allocation of Resources Without Limits

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-47865

Affected Products

Proftpd
Proftpd-Dfsg