Flexbyte Solar FTP Server
cpe:2.3:a:flexbyte:solar_ftp_server:*:*:*:*:*:*:*
- <= 2.1.1
This vulnerability is being actively exploited in the wild.
A denial-of-service vulnerability has been identified in Solar FTP Server versions through 2.1.1. The issue arises from improper handling of format strings in the USER command, leading to a read access violation in the sfsservice.exe process. This flaw causes the server to crash, creating a DoS condition.
Exploitation of this vulnerability causes the FTP server to crash, disrupting service availability.
The vulnerability can be reproduced by sending a crafted USER command that includes format specifiers. This can be done using a TCP connection to the FTP server's port (21) and sending the malformed USER command as the payload. The Metasploit module available in the Exploit Database can automate this process.
Users are advised to upgrade to Solar FTP Server version 2.1.2 or later, where this vulnerability has been addressed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.