← Vulnerability feed

Vulnerability record · CVE-2000-0573 · published 7 July 2000

CVE-2000-0573: wu-ftpd lreply format string allows remote command execution

Hp · Hp Ux

The lreply function in wu-ftpd 2.6.0 and earlier fails to sanitize an untrusted format string, letting a remote attacker inject format specifiers through the SITE EXEC command. Because the flaw is reachable over the network without authentication, it exposes the FTP service to full compromise.

10.0 CVSS 2.0 High EPSS 96% · top 0.1%
10.0CVSS 2.0 base score
96%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
28References
16 Jun 2026Last modified by NVD

Description

The lreply function in wu-ftpd 2.6.0 and earlier does not properly cleanse an untrusted format string, which allows remote attackers to execute arbitrary commands via the SITE EXEC command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: high.

critical priorityRemote unauthenticated command execution with a CVSS 2.0 score of 10 and very high EPSS probability makes this a top-priority patching target despite its age.

What it is

The lreply function in wu-ftpd 2.6.0 and earlier fails to sanitize an untrusted format string, letting a remote attacker inject format specifiers through the SITE EXEC command. Because the flaw is reachable over the network without authentication, it exposes the FTP service to full compromise.

Impact

An attacker can execute arbitrary commands on the FTP server, typically with the privileges of the wu-ftpd process, leading to complete loss of confidentiality, integrity and availability.

Attack surface

Reachable remotely over the network via the FTP SITE EXEC command; no authentication or user interaction is required per the CVSS vector AV:N/AC:L/Au:N.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented, but EPSS is very high (0.962 probability, 0.999 percentile), indicating strong likelihood of exploitation activity.

What to do

  • Upgrade wu-ftpd to a version later than 2.6.0 or apply the vendor patch referenced in CERT CA-2000-13 and the Red Hat, Caldera, FreeBSD and NetBSD advisories.
  • Disable or restrict the SITE EXEC command in the wu-ftpd configuration if it is not required.
  • Restrict FTP access to trusted networks and replace plain FTP with SFTP or FTPS where possible.
  • Monitor vendor advisories for HP-UX and other affected platforms and apply the corresponding patches.

Detection

  • Inspect FTP server logs for SITE EXEC commands containing format string specifiers such as %n, %s or %x.
  • Alert on unexpected child processes or shell activity spawned by the FTP daemon.
  • Monitor network traffic for anomalous FTP command sequences targeting SITE EXEC.
  • Correlate FTP authentication and command logs with host process creation events for signs of post-exploitation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1
ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc
http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html
http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html
http://marc.info/?l=bugtraq&m=96171893218000&w=2
http://marc.info/?l=bugtraq&m=96179429114160&w=2
http://marc.info/?l=bugtraq&m=96299933720862&w=2
http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt
http://www.cert.org/advisories/CA-2000-13.html PatchThird Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2000-039.html
http://www.securityfocus.com/bid/1387
http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000623091822.3321.qmail%40fiver.freemessage.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/4773
ftp://ftp.FreeBSD.org/pub/FreeBSD/CERT/advisories/FreeBSD-SA-00:29.wu-ftpd.asc.v1.1
ftp://ftp.auscert.org.au/pub/auscert/advisory/AA-2000.02
ftp://ftp.netbsd.org/pub/NetBSD/security/advisories/NetBSD-SA2000-009.txt.asc
http://archives.neohapsis.com/archives/bugtraq/2000-06/0244.html
http://archives.neohapsis.com/archives/bugtraq/2000-07/0017.html
http://marc.info/?l=bugtraq&m=96171893218000&w=2
http://marc.info/?l=bugtraq&m=96179429114160&w=2
http://marc.info/?l=bugtraq&m=96299933720862&w=2
http://www.calderasystems.com/support/security/advisories/CSSA-2000-020.0.txt
http://www.cert.org/advisories/CA-2000-13.html PatchThird Party AdvisoryUS Government Resource
http://www.redhat.com/support/errata/RHSA-2000-039.html
http://www.securityfocus.com/bid/1387
http://www.securityfocus.com/templates/archive.pike?list=1&msg=20000623091822.3321.qmail%40fiver.freemessage.com
https://exchange.xforce.ibmcloud.com/vulnerabilities/4773

Track CVE-2000-0573 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-1823PHP-CGI query string option injection enables remote code executionPHP versions before 5.3.12 and 5.4.x before 5.4.2, when run as a CGI script (php-cgi), mishandle query strings that lack an equals sign, allowing com…KEVEPSS 100%analysed10.0CVE-2012-0131Hp distributed computing environment vulnerabilityDistributed Computing Environment (DCE) 1.8 and 1.9 on HP HP-UX B.11.11 and B.11.23 allows remote attackers to cause a denial of service or possibly …EPSS 7.4%10.0CVE-2008-1668Hp-ux permissions and access controls vulnerabilityftpd.c in (1) wu-ftpd 2.4.2 and (2) ftpd in HP HP-UX B.11.11 assigns uid 0 to the FTP client in certain operating-system misconfigurations in which P…EPSS 4.5%10.0CVE-2008-1662Hp-ux vulnerabilityUnspecified vulnerability in the HP System Administration Manager (SAM) on HP-UX B.11.11 and B.11.23, when used to configure NFS, might allow remote …EPSS 4.4%10.0CVE-2007-6425Hp-ux memory buffer overflow vulnerabilityUnspecified vulnerability in HP-UX B.11.31, when running ARPA Transport, allows remote attackers to cause a denial of service via unknown vectors.EPSS 4.3%10.0CVE-2007-6195Hp-ux memory buffer overflow vulnerabilityBuffer overflow in the sw_rpc_agent_init function in swagentd in Software Distributor (SD), and possibly other DCE applications, in HP HP-UX B.11.11 …EPSS 14%10.0CVE-2007-4241Hp-ux vulnerabilityBuffer overflow in ldcconn in Hewlett-Packard (HP) Controller for Cisco Local Director on HP-UX 11.11i allows remote attackers to execute arbitrary c…EPSS 11%10.0CVE-2007-0915Hp-ux vulnerabilityDistributed SLS daemon (SLSd) on HP-UX B.11.11 allows remote attackers to overwrite arbitrary files and gain privileges via a crafted RPC request.EPSS 4.0%

Source: NIST National Vulnerability Database (record CVE-2000-0573), CISA KEV, FIRST EPSS (scores of 2026-09-22). This page is refreshed as NVD updates the record.