← Vulnerability feed

Vulnerability record · CVE-2006-3952 · published 1 August 2006

CVE-2006-3952: Easy File Sharing FTP Server PASS command stack buffer overflow

Efs Software · Efs Ftp Server

EFS Software Easy File Sharing FTP Server 2.0 contains a stack-based buffer overflow reachable through a long argument to the FTP PASS command. A remote attacker can send an oversized password value and overwrite stack memory, potentially achieving arbitrary code execution on the server. The record notes the provenance of the details is unknown and they come from third-party information, so the description should be treated as unverified.

7.5 CVSS 2.0 High EPSS 67% · top 0.7%
7.5CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
10References
16 Jun 2026Last modified by NVD

Description

Stack-based buffer overflow in EFS Software Easy File Sharing FTP Server 2.0 allows remote attackers to execute arbitrary code via a long argument to the PASS command. NOTE: the provenance of this information is unknown; the details are obtained from third party information.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is a remotely reachable, unauthenticated buffer overflow with high EPSS, but no KEV listing or confirmed public exploit in the record.

What it is

EFS Software Easy File Sharing FTP Server 2.0 contains a stack-based buffer overflow reachable through a long argument to the FTP PASS command. A remote attacker can send an oversized password value and overwrite stack memory, potentially achieving arbitrary code execution on the server. The record notes the provenance of the details is unknown and they come from third-party information, so the description should be treated as unverified.

Impact

Successful exploitation can let a remote attacker execute arbitrary code with the privileges of the FTP server process, giving full control of the affected host. Even without code execution, the overflow can crash the service, causing denial of service.

Attack surface

The flaw is reached over the network through the FTP service on its listening port, via the PASS command during authentication. No prior authentication is required because the PASS command is part of the login exchange, and no user interaction is needed.

Exploitation

The CVE is not listed in CISA KEV and no ransomware usage is documented. EPSS is high (0.66833, 99.257th percentile), indicating a meaningful probability of exploitation activity, but no public exploit reference is tagged in the supplied record.

What to do

  • Apply the vendor fix or upgrade Easy File Sharing FTP Server to a version later than 2.0 if one is available; the record does not name a fixed version, so confirm with the vendor.
  • If no patch exists, restrict FTP access to trusted networks and block inbound port 21 from the internet.
  • Run the FTP service under a low-privilege account and isolate it from sensitive data and management networks.
  • Replace the product with a maintained FTP server if the vendor no longer supports it.
  • Monitor vendor and advisory channels for updated guidance, since the supplied references are from 2006.

Detection

  • Alert on FTP PASS commands containing unusually long arguments or non-printable byte patterns.
  • Monitor the FTP service process for crashes or restarts that correlate with login attempts.
  • Inspect network traffic for oversized FTP control-channel commands and repeated failed logins from the same source.
  • Review host logs for unexpected child processes or command execution spawned by the FTP server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-3952 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2006-3952), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.