Vulnerability record · CVE-2004-1135 · published 10 January 2005
CVE-2004-1135: WS_FTP Server FTP command buffer overflows crash service
Ipswitch · Ws Ftp Server
WS_FTP Server 5.03 (2004.10.14) contains multiple buffer overflows reachable through long SITE, XMKD, MKD and RNFR FTP commands. The record describes only a denial-of-service outcome (service crash), not code execution, so the practical risk is availability loss rather than host compromise.
Description
Multiple buffer overflows in WS_FTP Server 5.03 2004.10.14 allow remote attackers to cause a denial of service (service crash) via long (1) SITE, (2) XMKD, (3) MKD, and (4) RNFR commands.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
medium priorityRemote unauthenticated denial of service with public exploit code and high EPSS, but impact is limited to service availability and the affected product is a long-obsolete release.
What it is
WS_FTP Server 5.03 (2004.10.14) contains multiple buffer overflows reachable through long SITE, XMKD, MKD and RNFR FTP commands. The record describes only a denial-of-service outcome (service crash), not code execution, so the practical risk is availability loss rather than host compromise.
Impact
A remote attacker can crash the WS_FTP Server service, interrupting file transfer availability for all users. No confidentiality or integrity impact is stated in the CVSS vector.
Attack surface
Reachable over the network via the FTP service by sending oversized SITE, XMKD, MKD or RNFR commands. The CVSS vector AV:N/AC:L/Au:N indicates no authentication is required and no user interaction is needed.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high at roughly 0.50 (98.8th percentile), and the references include a public exploit write-up on Securiteam, indicating public proof-of-concept availability.
What to do
- Upgrade WS_FTP Server to a version later than 5.03 2004.10.14; the record does not name a fixed version, so confirm with the vendor.
- If patching is not possible, restrict FTP access to trusted networks and disable or filter SITE, XMKD, MKD and RNFR commands where the server configuration allows.
- Place the FTP service behind a filtering proxy or IPS that rejects abnormally long FTP command arguments.
- Monitor the service for repeated crashes and restart automatically to limit downtime.
- Retire or isolate the end-of-life 5.03 release, which is no longer supported.
Detection
- Alert on FTP command lines exceeding normal length for SITE, XMKD, MKD or RNFR in server or IDS logs.
- Monitor WS_FTP Server process crashes and unexpected service restarts.
- Baseline normal FTP command argument lengths and flag outliers from external source IPs.
- Review network logs for repeated malformed FTP commands from a single source.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2004-1135 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1135), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.