Vulnerability record · CVE-2004-1626 · published 22 October 2004
CVE-2004-1626: Ability Server STOR command buffer overflow allows remote code execution
Code Crafters · Ability Server
Ability Server 2.34 (and possibly other versions) contains a buffer overflow in its handling of the STOR command. A remote attacker can send an overly long STOR argument to corrupt memory and potentially execute arbitrary code on the FTP service. The flaw matters because it is network-reachable and requires no authentication.
Description
Buffer overflow in Ability Server 2.34, and possibly other versions, allows remote attackers to execute arbitrary code via a long STOR command.
AV:N/AC:L/Au:N/C:N/I:N/A:P
Automated analysis
high priorityNetwork-reachable, unauthenticated buffer overflow with public exploit references and very high EPSS, though no KEV listing and only a medium CVSS 2.0 score.
What it is
Ability Server 2.34 (and possibly other versions) contains a buffer overflow in its handling of the STOR command. A remote attacker can send an overly long STOR argument to corrupt memory and potentially execute arbitrary code on the FTP service. The flaw matters because it is network-reachable and requires no authentication.
Impact
An attacker can crash the service or, if the overflow is successfully shaped, execute arbitrary code with the privileges of the Ability Server process. The CVSS 2.0 vector scores only partial availability impact, so the record understates the potential for code execution.
Attack surface
Reached over the network via the FTP service by sending a crafted STOR command; the CVSS vector AV:N/AC:L/Au:N indicates no authentication is required. No user interaction is described.
Exploitation
CISA KEV does not list this CVE, but EPSS is 0.67387 (99.27th percentile) and multiple references are tagged Exploit, indicating public exploit material exists.
What to do
- Patch or upgrade Ability Server to a version that fixes the STOR buffer overflow; if no fixed version is available, retire or replace the product.
- Restrict network access to the FTP service to trusted hosts and block it from the internet.
- Run the service under a low-privilege account and isolate it from sensitive data and systems.
- Enforce strict input length limits on FTP commands at a proxy or WAF where feasible.
- Monitor vendor and CERT/CC advisories for updated guidance on Ability Server.
Detection
- Inspect FTP server logs for STOR commands with abnormally long arguments or malformed syntax.
- Alert on crashes or restarts of the Ability Server process.
- Monitor for unexpected child processes or outbound connections spawned by the FTP service.
- Use network IDS signatures for FTP STOR buffer overflow attempts against Ability Server.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://marc.info/?l=bugtraq&m=109850947508816&w=2 | |
| http://secunia.com/advisories/12941 | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/857846 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/11030 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/11508 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17823 | |
| http://marc.info/?l=bugtraq&m=109850947508816&w=2 | |
| http://secunia.com/advisories/12941 | Vendor Advisory |
| http://www.kb.cert.org/vuls/id/857846 | Third Party AdvisoryUS Government Resource |
| http://www.osvdb.org/11030 | ExploitVendor Advisory |
| http://www.securityfocus.com/bid/11508 | ExploitVendor Advisory |
| https://exchange.xforce.ibmcloud.com/vulnerabilities/17823 |
Track CVE-2004-1626 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2004-1626), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.