CVE-2004-2074 is a format string vulnerability in BolinTech Dream FTP Server 1.02, allowing local users to trigger a denial of service by injecting format string specifiers into the PASS or RETR commands. With a CVSS score of 5.0 and an EPSS score indicating higher exploitability than 98% of CVEs, this vulnerability poses a moderate risk, primarily leading to system crashes. While not listed on the KEV catalog, exploit code is publicly available via Metasploit and ExploitDB, and it has garnered significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1.02CPE matchmatch criteria | cpe:2.3:a:bolintech:dream_ftp_server:1.02:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.