CVE-2023-22551 is a denial-of-service vulnerability affecting the "FTP (aka 'Implementation of a simple FTP client and server')" project through commit 96c1a35. Remote attackers can trigger excessive memory consumption by repeatedly establishing and terminating client connections, as the software allocates memory without properly freeing it. This vulnerability has a CVSS score of 7.5 (High), indicating it can be exploited remotely with low complexity and no user interaction, leading to high availability impact. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2012-03-28CPE matchmatch criteria | cpe:2.3:a:ftp_project:ftp:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.