← Vulnerability feed

Vulnerability record · CVE-2006-2212 · published 5 May 2006

CVE-2006-2212: KarjaSoft Sami FTP Server USER/PASS buffer overflow

KKarjasoft · Sami Ftp Server

Sami FTP Server 2.0.2 and earlier contains a buffer overflow in the handling of the USER and PASS commands. A remote attacker can send an overly long username or password to corrupt memory and potentially execute arbitrary code on the FTP service.

6.4 CVSS 2.0 Medium EPSS 59% · top 0.9%
6.4CVSS 2.0 base score
59%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
12References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in KarjaSoft Sami FTP Server 2.0.2 and earlier allows remote attackers to execute arbitrary code via a long (1) USER or (2) PASS command.

AV:N/AC:L/Au:N/C:P/I:P/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable without authentication and can lead to code execution, and EPSS is very high, though the record lacks confirmed exploit tags and a fixed version.

What it is

Sami FTP Server 2.0.2 and earlier contains a buffer overflow in the handling of the USER and PASS commands. A remote attacker can send an overly long username or password to corrupt memory and potentially execute arbitrary code on the FTP service.

Impact

Successful exploitation can allow an attacker to execute arbitrary code with the privileges of the FTP server process. The CVSS 2.0 vector indicates partial confidentiality and integrity impact, with no availability impact recorded.

Attack surface

The flaw is reachable over the network through the FTP service, with no authentication required because the overflow occurs during the USER or PASS command before login completes. No user interaction is needed.

Exploitation

The record is not listed in CISA KEV and no ransomware associations are documented. EPSS is high at 0.58229 (99.051st percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.

What to do

  • Upgrade Sami FTP Server to a version later than 2.0.2 if one is available; the record does not name a fixed version.
  • If the product is unsupported or no patch exists, retire it or isolate it behind strict network controls.
  • Restrict FTP access to trusted networks and block inbound TCP/21 from untrusted sources.
  • Run the FTP service with least privilege and not as a privileged account.
  • Monitor vendor and vulnerability feeds for a fixed release or replacement guidance.

Detection

  • Inspect FTP server logs for USER or PASS commands with abnormally long arguments.
  • Alert on FTP service crashes, restarts, or unexpected process termination.
  • Monitor for post-exploitation behavior such as new processes or outbound connections from the FTP host.
  • Use network IDS signatures for oversized FTP USER/PASS commands if available.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-2212 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2006-2212), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.