VulnerabilityModified
CVE-2001-1021
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
HIGH 7.5EPSS 42.1%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 42.1%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
Buffer overflows in WS_FTP 2.02 allow remote attackers to execute arbitrary code via long arguments to (1) DELE, (2) MDTM, (3) MLST, (4) MKD, (5) RMD, (6) RNFR, (7) RNTO, (8) SIZE, (9) STAT, (10) XMKD, or (11) XRMD.
- CVSS 2.0
- 7.5 HIGHAV:N/AC:L/Au:N/C:P/I:P/A:P
- EPSS
- 42.14% probability · 99th percentile
- CISA KEV
- Not listed
- Affected
- progress/ws ftp server
- Source
- cve@mitre.org
References
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.htmlExploit, Patch, Vendor Advisory
- http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6911
- http://archives.neohapsis.com/archives/bugtraq/2001-07/0610.htmlExploit, Patch, Vendor Advisory
- http://www.ipswitch.com/Support/WS_FTP-Server/patch-upgrades.htmlPatch
- https://exchange.xforce.ibmcloud.com/vulnerabilities/6911
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.