CVE-2021-40524 describes a denial-of-service vulnerability in Pure-FTPd versions 1.0.23 through 1.0.49, where an attacker can bypass the max_filesize quota to upload unbounded files, potentially crashing the server. This high-severity flaw (CVSS 7.5) is easily exploitable over the network without authentication, leading to high availability impact. While not currently listed on CISA's KEV catalog or showing active exploitation, a Nuclei template exists, indicating potential for exploit development, though there is minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.0.23, < 1.0.50CPE matchmatch criteria | cpe:2.3:a:pureftpd:pure-ftpd:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.