Vulnerability record · CVE-1999-1510 · published 17 May 1999
CVE-1999-1510: Bisonware FTP Server buffer overflow in USER, LIST and CWD commands
BBisonware · Bisonware Ftp Server
Bisonware FTP server prior to 4.1 contains buffer overflows reachable through long USER, LIST, or CWD commands. A remote attacker can crash the service and possibly execute arbitrary commands on the host. The record is old and thin, with no patch reference or affected-version detail beyond the pre-4.1 statement.
Description
Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityRemote, unauthenticated buffer overflow with possible command execution and very high EPSS, though the record is old and lacks patch and exploit detail.
What it is
Bisonware FTP server prior to 4.1 contains buffer overflows reachable through long USER, LIST, or CWD commands. A remote attacker can crash the service and possibly execute arbitrary commands on the host. The record is old and thin, with no patch reference or affected-version detail beyond the pre-4.1 statement.
Impact
An attacker gains denial of service against the FTP service and, per the description, possibly arbitrary command execution on the server. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.
Attack surface
The flaw is reached over the network through the FTP command channel, with no authentication or user interaction required per the AV:N/AC:L/Au:N vector. Commands such as USER, LIST and CWD are typically available before or during login.
Exploitation
Not listed in CISA KEV and no exploit tag appears in the references, but EPSS is high at roughly 0.67 probability (99th percentile), indicating elevated predicted exploitation activity. No public exploit code is confirmed by the supplied references.
What to do
- Upgrade Bisonware FTP server to version 4.1 or later, or replace it with a maintained FTP server.
- Restrict FTP access to trusted networks and block port 21 from the internet where the service is not required.
- Enforce strict length limits on FTP command input at any fronting proxy or firewall that inspects the command channel.
- Run the FTP service with least privilege and isolate it from sensitive data and management networks.
- Monitor vendor channels for a definitive patch since this record provides no patch reference.
Detection
- Alert on FTP command lines exceeding normal length, especially USER, LIST and CWD arguments.
- Monitor for repeated FTP service crashes or restarts that correlate with inbound connections.
- Watch for unexpected child processes or shell activity spawned by the FTP service account.
- Review FTP server logs for anomalous command sequences preceding a crash or disconnect.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-1999-1510 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-1999-1510), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.