CVE-2004-1848 describes a denial of service vulnerability in Ipswitch WS_FTP Server 4.0.2 and Progress WS_FTP Server. Remote attackers can exploit this by sending a REST command with a large size argument, followed by a smaller STOR command, leading to excessive disk consumption and bypassing file size restrictions. This unauthenticated network-based attack has low complexity, resulting in a partial denial of service (disk consumption), reflected by its CVSS score of 5.0 (Medium). Although not listed on CISA's KEV catalog and lacking public exploit code in Metasploit or ExploitDB, it is noted as "Active" on the Hot List and has received some community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.0_1CPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:3.0_1:*:*:*:*:*:*:* | ||
4.01CPE matchmatch criteria | cpe:2.3:a:ipswitch:ws_ftp_server:4.01:*:*:*:*:*:*:* | ||
1.0.1CPE matchmatch criteria | cpe:2.3:a:progress:ws_ftp_server:1.0.1:*:*:*:*:*:*:* | ||
1.0.2CPE matchmatch criteria | cpe:2.3:a:progress:ws_ftp_server:1.0.2:*:*:*:*:*:*:* | ||
1.0.3CPE matchmatch criteria | cpe:2.3:a:progress:ws_ftp_server:1.0.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.