Vulnerability record · CVE-2000-0574 · published 7 July 2000
CVE-2000-0574: FTP servers format string flaw in setproctitle allows remote command execution
Openbsd · Ftpd
Several FTP server implementations (OpenBSD ftpd, NetBSD ftpd, ProFTPd, Opieftpd, and wu-ftpd) fail to sanitize untrusted format strings passed to the setproctitle/set_proc_title function. A remote attacker can supply crafted input that is interpreted as a format string, leading to a denial of service or arbitrary command execution. The flaw matters because it is reachable over the network without authentication and affects widely deployed FTP daemons.
Description
FTP servers such as OpenBSD ftpd, NetBSD ftpd, ProFTPd and Opieftpd do not properly cleanse untrusted format strings that are used in the setproctitle function (sometimes called by set_proc_title), which allows remote attackers to cause a denial of service or execute arbitrary commands.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityRemote, unauthenticated, low-complexity flaw with potential for arbitrary command execution and a high EPSS score, though no confirmed in-the-wild exploitation is documented.
What it is
Several FTP server implementations (OpenBSD ftpd, NetBSD ftpd, ProFTPd, Opieftpd, and wu-ftpd) fail to sanitize untrusted format strings passed to the setproctitle/set_proc_title function. A remote attacker can supply crafted input that is interpreted as a format string, leading to a denial of service or arbitrary command execution. The flaw matters because it is reachable over the network without authentication and affects widely deployed FTP daemons.
Impact
An attacker can crash the FTP service or, depending on the platform and stack layout, execute arbitrary commands with the privileges of the FTP daemon.
Attack surface
Reached remotely over the network via the FTP service; the CVSS vector (AV:N/AC:L/Au:N) indicates no authentication and low complexity, and the description does not require user interaction.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented, but EPSS is high (0.5887, 99th percentile), suggesting meaningful exploitation likelihood; reference tags include a CERT advisory marked Patch.
What to do
- Apply vendor patches or upgrade to fixed FTP server versions per CERT CA-2000-13 and the NetBSD advisory.
- Disable or restrict FTP service where not required, and limit access to trusted networks.
- Run FTP daemons with least privilege and in a sandboxed or chrooted environment.
- Monitor vendor advisories for the specific ftpd implementation in use and track its patch status.
Detection
- Inspect FTP server logs for malformed or format-specifier-laden input in commands and arguments.
- Monitor for unexpected FTP daemon crashes or restarts that could indicate format string probing.
- Watch for anomalous child processes or command execution spawned by the FTP daemon.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2000-0574 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2000-0574), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.