vendor:
netek
by:
Lawrence Amer
7.5
CVSS
HIGH
Denial of Service
400
CWE
Product Name: netek
Affected Version From: 0.8.2
Affected Version To: 0.8.2
Patch Exists: NO
Related CWE: N/A
CPE: netek.berlios
Metasploit:
N/A
Other Scripts:
N/A
Platforms Tested: Windows XP, Windows 7
2020
netek 0.8.2 FTP Denial of Service
netek 0.8.2 FTP is vulnerable to Denial of Service attack. An attacker can send a crafted payload of 5000 'A' characters and 1000 'B' characters to the default port 30817 to crash the server. This will cause the CPU usage to reach 100%.
Mitigation:
Disable the FTP service if not required. If required, use a firewall to restrict access to the FTP service from untrusted sources.