← Vulnerability feed

Vulnerability record · CVE-2005-0277 · published 2 May 2005

CVE-2005-0277: 3Com 3CDaemon FTP Service Buffer Overflow

3com · 3cdaemon

The FTP service in 3Com 3CDaemon 2.0 revision 10 contains a buffer overflow that can be triggered by a long username in the USER command or a long argument in commands such as cd, send, or ls. A remote attacker can crash the service and potentially execute arbitrary code.

5.0 CVSS 2.0 Medium EPSS 62% · top 0.9%
5.0CVSS 2.0 base score
62%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References, 2 tagged exploit
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the FTP service in 3Com 3CDaemon 2.0 revision 10 allows remote attackers to cause a denial of service (application crash) and execute arbitrary code via (1) a long username in the USER command or (2) an FTP command that contains a long argument, such as cd, send, or ls.

AV:N/AC:L/Au:N/C:N/I:N/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe vulnerability is remotely exploitable without authentication, has public exploit code, and a high EPSS score, though the CVSS v2 score is only medium.

What it is

The FTP service in 3Com 3CDaemon 2.0 revision 10 contains a buffer overflow that can be triggered by a long username in the USER command or a long argument in commands such as cd, send, or ls. A remote attacker can crash the service and potentially execute arbitrary code.

Impact

An attacker can cause a denial of service by crashing the FTP service and may be able to execute arbitrary code on the affected host.

Attack surface

The flaw is reachable over the network through the FTP service; no authentication is required because the overflow occurs in the USER command or other commands before login. No user interaction is needed.

Exploitation

The record is not listed in CISA KEV, but EPSS is high at 0.61909 (99.135th percentile) and a SecurityFocus reference is tagged Exploit, indicating public exploit code exists.

What to do

  • Apply any available vendor patch or upgrade to a fixed version of 3CDaemon; if none exists, discontinue use of the affected FTP service.
  • Restrict network access to the FTP service to trusted hosts only.
  • Disable the FTP service if it is not required.
  • Monitor vendor and vulnerability feeds for updated guidance or patches.

Detection

  • Inspect FTP server logs for USER commands or other FTP commands containing unusually long arguments.
  • Monitor for repeated FTP service crashes or restarts.
  • Use network monitoring to detect oversized FTP commands sent to the service.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2005-0277 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2005-0277), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.