{"id":"CVE-2019-25588","title":"BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address","summary":"BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address opt…","severity":"medium","cvss":6.2,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H","cvssSource":"cna","cwe":["CWE-1282"],"vendor":"Bpftpserver","product":"BulletProof FTP Server","affected":["bulletproof_ftp_server 2019.0.0.50"],"ssvc":{"exploitation":"poc","automatable":"no","technicalImpact":"partial","timestamp":"2026-03-24T14:01:17.488103Z"},"exploitAvailable":true,"published":"2026-03-22","updated":"2026-10-01","sourceUpdated":"2026-10-01T15:19:19.736Z","source":"CVEORG","sourceUrl":"https://www.cve.org/CVERecord?id=CVE-2019-25588","references":[{"url":"https://www.exploit-db.com/exploits/46875","label":"ExploitDB-46875"},{"url":"http://bpftpserver.com/","label":"Official Product Homepage"},{"url":"http://bpftpserver.com/products/bpftpserver/windows/download","label":"Product Reference"},{"url":"https://www.vulncheck.com/advisories/bulletproof-ftp-server-denial-of-service-via-dns-address","label":"VulnCheck Advisory: BulletProof FTP Server 2019.0.0.50 Denial of Service via DNS Address"}],"tags":["cve.org","exploit-available"],"epss":0.00171,"epssPercentile":0.05833,"ingestedAt":"2026-10-01T15:48:17.884Z","slug":"CVE-2019-25588","body":"## Overview\n\nBulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the DNS Address field that allows local attackers to crash the application by supplying an excessively long string. Attackers can enable the DNS Address option in the Firewall settings and paste a buffer of 700 bytes to trigger a crash when the Test function is invoked.\n\n## Affected\n\n- `bulletproof_ftp_server 2019.0.0.50`\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":46,"depthScoreParts":{"impact":34.1,"likelihood":0,"exploitation":12,"ransomware":0},"changes":[]}