QID 27394

Date Published: 2023-10-03

QID 27394: VSFTPD Denial of Service (DoS) Vulnerability

VSftpd is a secure FTP server for Linux, UNIX, and similar operating systems.

CVE-2021-30047: VSFTPD 3.0.3 allows attackers to cause a denial of service due to limited number of connections allowed.

Affected Versions:
VSFTPD version 3.0.3

QID Detection Logic:

Successful exploitation of this vulnerability may allows attackers to cause a denial of service due to limited number of connections allowed.

  • CVSS V3 rated as High - 7.5 severity.
  • CVSS V2 rated as Medium - 5 severity.
  • Solution
    Customers are advised to upgrade to VSFTPD 3.0.4 or later to mitigate this vulnerability.
    Vendor References

    CVEs related to QID 27394

    Software Advisories
    Advisory ID Software Component Link
    VSFTPD Release Notes URL Logo security.appspot.com/vsftpd.html#download