CVE-2019-25588CWE-1282

BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address

Medium · published March 22, 2026

CVSS v4.0
6.9
EPSS
0%
Percentile
6.7
In the wild
Unconfirmed
What it is

BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.

The record
Technical detail
CVSS v4.0
6.9 · MEDIUM
Vector
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
0.00171 · 6.7th percentile
Weakness
CWE-1282 · Assumed-Immutable Data is Stored in Writable Memory
Published
2026-03-22T00:11Z
EPSS history
Timeline
  • 22 MAR 00:11Z
    BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address
    cvelistv5