vendor:
BulletProof FTP Server
by:
Victor Mondragón
7.8
CVSS
HIGH
Denial of Service
400
CWE
Product Name: BulletProof FTP Server
Affected Version From: 2019.0.0.50
Affected Version To: 2019.0.0.50
Patch Exists: Yes
Related CWE: N/A
CPE: a:bpftpserver:bulletproof_ftp_server
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows 7 x64 Service Pack 1
2018
BulletProof FTP Server 2019.0.0.50 – Denial of Service (PoC)
A denial of service vulnerability exists in BulletProof FTP Server 2019.0.0.50 when a maliciously crafted payload is sent to the SMTP Server field. An attacker can leverage this vulnerability to cause a denial of service condition.
Mitigation:
Upgrade to the latest version of BulletProof FTP Server.