Denial of Service Vulnerability in Serv-U FTP Server by SolarWinds
CVE-2009-0967
Currently unrated
Key Information:
- Vendor
Solarwinds
- Status
- Vendor
- CVE Published:
- 19 March 2009
Badges
๐พ Exploit Exists๐ก Public PoC
What is CVE-2009-0967?
The Serv-U FTP Server, versions 7.0.0.1 to 7.4.0.1, is susceptible to a denial of service attack. Remote authenticated users can exploit this vulnerability by sending a large number of SMNT commands without any accompanying arguments. This flood of requests can lead to a service hang, rendering the FTP server inoperable and disrupting service availability for legitimate users.
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.