HIGH

CVE-2021-40524

CVSS v3

7.5

HIGH

EPSS Score

24.0%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)

Technical details

Published
9/5/2021

Frequently asked questions

What is CVE-2021-40524?

In Pure-FTPd before 1.0.50, an incorrect max_filesize quota mechanism in the server allows attackers to upload files of unbounded size, which may lead to denial of service or a server hang. This occurs because a certain greater-than-zero test does not anticipate an initial -1 value. (Versions 1.0.23 through 1.0.49 are affected.)

Is CVE-2021-40524 actively exploited?

Active exploitation of CVE-2021-40524 has not been confirmed. The EPSS score is 24.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-40524?

CVE-2021-40524 has a CVSS v3 base score of 7.5 (HIGH severity).

Is CVE-2021-40524 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.