🔐 CVE Alert

CVE-2018-25229

MEDIUM 5.5

BulletProof FTP Server 2019.0.0.50 Denial of Service via SMTP

CVSS Score
5.5
EPSS Score
0.0%
EPSS Percentile
0th

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the SMTP configuration interface that allows local attackers to crash the application by supplying an oversized string. Attackers can input a buffer of 257 'A' characters in the SMTP Server field and trigger a crash by clicking the Test button.

CWE CWE-1282
Vendor bpftpserver
Product bulletproof ftp server
Published Mar 30, 2026
Last Updated Mar 30, 2026
Stay Ahead of the Next One

Get instant alerts for bpftpserver bulletproof ftp server

Be the first to know when new medium vulnerabilities affecting bpftpserver bulletproof ftp server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

Bpftpserver / BulletProof FTP Server
2019.0.0.50

References

NVD ↗ CVE.org ↗ EPSS Data ↗
exploit-db.com: https://www.exploit-db.com/exploits/46422 bpftpserver.com: http://bpftpserver.com/ bpftpserver.com: http://bpftpserver.com/products/bpftpserver/windows/download vulncheck.com: https://www.vulncheck.com/advisories/bulletproof-ftp-server-denial-of-service-via-smtp

Credits

Victor Mondragón