CVE-2000-0573 describes a critical format string vulnerability in the lreply function of wu-ftpd versions 2.6.0 and earlier, including those on HP-UX systems. This flaw allows unauthenticated remote attackers to execute arbitrary commands by sending specially crafted input via the SITE EXEC command. With a CVSS score of 10.0, this vulnerability is highly severe, enabling complete compromise of confidentiality, integrity, and availability with low attack complexity. While not on the KEV catalog, multiple public exploits exist, including Metasploit modules and several ExploitDB entries, indicating readily available tools for exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.00CPE matchmatch criteria | cpe:2.3:o:hp:hp-ux:11.00:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.