← Vulnerability feed

Vulnerability record · CVE-1999-1510 · published 17 May 1999

CVE-1999-1510: Bisonware FTP Server buffer overflow in USER, LIST and CWD commands

BBisonware · Bisonware Ftp Server

Bisonware FTP server prior to 4.1 contains buffer overflows reachable through long USER, LIST, or CWD commands. A remote attacker can crash the service and possibly execute arbitrary commands on the host. The record is old and thin, with no patch reference or affected-version detail beyond the pre-4.1 statement.

7.5 CVSS 2.0 High EPSS 67% · top 0.7%
7.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
16 Jun 2026Last modified by NVD

Description

Buffer overflows in Bisonware FTP server prior to 4.1 allow remote attackers to cause a denial of service, and possibly execute arbitrary commands, via long (1) USER, (2) LIST, or (3) CWD commands.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityRemote, unauthenticated buffer overflow with possible command execution and very high EPSS, though the record is old and lacks patch and exploit detail.

What it is

Bisonware FTP server prior to 4.1 contains buffer overflows reachable through long USER, LIST, or CWD commands. A remote attacker can crash the service and possibly execute arbitrary commands on the host. The record is old and thin, with no patch reference or affected-version detail beyond the pre-4.1 statement.

Impact

An attacker gains denial of service against the FTP service and, per the description, possibly arbitrary command execution on the server. The CVSS 2.0 vector rates partial confidentiality, integrity and availability impact.

Attack surface

The flaw is reached over the network through the FTP command channel, with no authentication or user interaction required per the AV:N/AC:L/Au:N vector. Commands such as USER, LIST and CWD are typically available before or during login.

Exploitation

Not listed in CISA KEV and no exploit tag appears in the references, but EPSS is high at roughly 0.67 probability (99th percentile), indicating elevated predicted exploitation activity. No public exploit code is confirmed by the supplied references.

What to do

  • Upgrade Bisonware FTP server to version 4.1 or later, or replace it with a maintained FTP server.
  • Restrict FTP access to trusted networks and block port 21 from the internet where the service is not required.
  • Enforce strict length limits on FTP command input at any fronting proxy or firewall that inspects the command channel.
  • Run the FTP service with least privilege and isolate it from sensitive data and management networks.
  • Monitor vendor channels for a definitive patch since this record provides no patch reference.

Detection

  • Alert on FTP command lines exceeding normal length, especially USER, LIST and CWD arguments.
  • Monitor for repeated FTP service crashes or restarts that correlate with inbound connections.
  • Watch for unexpected child processes or shell activity spawned by the FTP service account.
  • Review FTP server logs for anomalous command sequences preceding a crash or disconnect.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-1999-1510 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-1999-1510), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.