← Vulnerability feed

Vulnerability record · CVE-2004-2111 · published 31 December 2004

CVE-2004-2111: Serv-U FTP Server site chmod stack buffer overflow

Solarwinds · Serv U File Server

Serv-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can issue FTP commands can overwrite stack memory and potentially execute arbitrary code on the server.

8.5 CVSS 2.0 High EPSS 87% · top 0.3% CWE-119 · Memory buffer overflow
8.5CVSS 2.0 base score
87%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in the site chmod command in Serv-U FTP Server before 4.2 allows remote attackers to execute arbitrary code via a long filename.

AV:N/AC:M/Au:S/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 18 September 2026. Confidence: medium.

high priorityRemote code execution with a CVSS 2.0 score of 8.5 and very high EPSS, but exploitation requires some authentication and the product is a legacy version.

What it is

Serv-U FTP Server before 4.2 has a stack-based buffer overflow in the site chmod command, triggered by a long filename. A remote attacker who can issue FTP commands can overwrite stack memory and potentially execute arbitrary code on the server.

Impact

Successful exploitation gives the attacker arbitrary code execution in the context of the Serv-U service, typically SYSTEM on Windows, leading to full host compromise. Even without code execution, the overflow can crash the service.

Attack surface

Reached over the network through the FTP service by sending a crafted site chmod command with an oversized filename. The CVSS vector (AV:N/AC:M/Au:S) indicates network access with some complexity and that some level of authentication or privilege is required, so valid FTP credentials are likely needed.

Exploitation

Public exploit references are tagged on Bugtraq and SecurityFocus, and EPSS is very high (0.86867, 99.7th percentile), though the CVE is not listed in CISA KEV. No ransomware association is documented.

What to do

  • Upgrade Serv-U FTP Server to version 4.2 or later, which fixes the overflow.
  • If upgrade is not possible, restrict FTP access to trusted networks and disable or block the site chmod command.
  • Enforce strong, unique FTP credentials and least-privilege accounts to limit who can reach the vulnerable command.
  • Run the FTP service under a low-privilege account rather than SYSTEM to reduce the impact of code execution.
  • Monitor vendor advisories for this legacy product and plan migration off end-of-life versions.

Detection

  • Inspect FTP command logs for site chmod requests containing unusually long filenames or non-printable bytes.
  • Alert on Serv-U service crashes or restarts, which may indicate a failed overflow attempt.
  • Monitor for unexpected child processes or command shells spawned by the Serv-U service process.
  • Use network IDS signatures for oversized FTP command arguments targeting the site chmod verb.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2004-2111 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

10.0CVE-2009-4006Serv-U FTP Server TEA Decoding Stack Buffer OverflowRhinoSoft Serv-U FTP server versions before 9.1.0.0 contain a stack-based buffer overflow in the TEA decoding algorithm. A remote attacker can trigge…EPSS 83%analysed10.0CVE-2004-2532Solarwinds serv-u file server vulnerabilityServ-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands …EPSS 15%10.0CVE-2004-0330Serv-U FTP MDTM time zone buffer overflow allows remote code executionServ-U FTP versions before 5.0.0.4 contain a buffer overflow in the handling of the time zone argument to the MDTM command. A remote authenticated FT…EPSS 85%analysed9.0CVE-2011-4800Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in Serv-U FTP Server before 11.1.0.5 allows remote authenticated users to read and write arbitrary files, and list …EPSS 7.3%9.0CVE-2008-4501Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Serv-U 7.0.0.1 through 7.3, including 7.2.0.1, allows remote authenticated users to overwrite …EPSS 11%7.8CVE-2009-1031Solarwinds serv-u file server path traversal vulnerabilityDirectory traversal vulnerability in the FTP server in Rhino Software Serv-U File Server 7.0.0.1 through 7.4.0.1 allows remote attackers to create ar…EPSS 11%7.5CVE-2001-1463Solarwinds serv-u file server vulnerabilityThe remote administration client for RhinoSoft Serv-U 3.0 sends the user password in plaintext even when S/KEY One-Time Password (OTP) authentication…EPSS 3.2%6.1CVE-2021-25179Solarwinds serv-u file server cross-site scripting vulnerabilitySolarWinds Serv-U before 15.2 is affected by Cross Site Scripting (XSS) via the HTTP Host header.EPSS 1.4%

Source: NIST National Vulnerability Database (record CVE-2004-2111), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.