CVE-2019-25588 is a denial of service vulnerability present in BulletProof FTP Server version 2019.0.0.50. This flaw allows a local attacker to crash the application by supplying an excessively long string to the DNS Address field within the Firewall settings. Rated Medium with a CVSS score of 6.2, the vulnerability has low attack complexity and requires local access to trigger a high impact on availability. There is no evidence of active exploitation, and no public exploit code is available in common databases like Metasploit or ExploitDB. Furthermore, there is no community discussion or media coverage surrounding this CVE, indicating a very low current risk of widespread exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019.0.0.50CPE matchmatch criteria | cpe:2.3:a:bpftpserver:bulletproof_ftp_server:2019.0.0.50:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.