CVE-2019-25686: Core FTP 2.0 build 653 PBSZ Unauthenticated Denial of Service
Core FTP 2.0 build 653 contains a denial of service vulnerability in the PBSZ command that allows unauthenticated attackers to crash the service by sending a malformed command with an oversized buffer. Attackers can send a PBSZ command with a payload exceeding 211 bytes to trigger an access violation and crash the FTP server process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2019-25686?
CVE-2019-25686 has a severity rating of 8.7, classified as high.
How do I fix CVE-2019-25686?
To remediate CVE-2019-25686, update to a newer version of Core FTP that addresses this denial of service vulnerability.
What type of vulnerability is CVE-2019-25686?
CVE-2019-25686 is a denial of service vulnerability caused by the PBSZ command in Core FTP.
Who is affected by CVE-2019-25686?
Users of Core FTP version 2.0 build 653 are at risk of CVE-2019-25686.
What can an attacker do with CVE-2019-25686?
An attacker can exploit CVE-2019-25686 by sending a malformed PBSZ command to crash the Core FTP service.