← Vulnerability feed

Vulnerability record · CVE-2006-6183 · published 1 December 2006

CVE-2006-6183: 3Com 3CTftpSvc TFTP mode field stack buffer overflow

3com · 3ctftpsvc

3Com 3CTftpSvc 2.0.1 (and possibly earlier) contains multiple stack-based buffer overflows triggered by an overlong mode field in TFTP GET or PUT commands. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The flaw is remotely reachable over the network with no credentials required.

10.0 CVSS 2.0 High EPSS 70% · top 0.6% CWE-119 · Memory buffer overflow
10.0CVSS 2.0 base score
70%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
14References, 4 tagged exploit
16 Jun 2026Last modified by NVD

Description

Multiple stack-based buffer overflows in 3Com 3CTftpSvc 2.0.1, and possibly earlier, allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a long mode field (aka transporting mode) in a (1) GET or (2) PUT command.

AV:N/AC:L/Au:N/C:C/I:C/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityRemote, unauthenticated, low-complexity buffer overflow with a CVSS 2.0 score of 10, public exploit references, and a very high EPSS probability.

What it is

3Com 3CTftpSvc 2.0.1 (and possibly earlier) contains multiple stack-based buffer overflows triggered by an overlong mode field in TFTP GET or PUT commands. A remote, unauthenticated attacker can crash the service or potentially execute arbitrary code on the host. The flaw is remotely reachable over the network with no credentials required.

Impact

An attacker can cause a denial of service by crashing the TFTP service, or potentially execute arbitrary code with the privileges of the service process. Successful code execution would give the attacker a foothold on the affected host.

Attack surface

Reached over the network via the TFTP service, which is inherently unauthenticated; no user interaction is required. The CVSS vector AV:N/AC:L/Au:N/C:C/I:C/A:C confirms remote, low-complexity, unauthenticated exploitation.

Exploitation

CISA KEV does not list this CVE, but EPSS is very high (0.70293, 99.35th percentile) and two SecurityFocus references are tagged Exploit, indicating public exploit material exists. No ransomware group usage is documented.

What to do

  • Apply the vendor patch or upgrade 3CTftpSvc to a fixed version if one is available; if no fix exists, retire or replace the product.
  • Restrict TFTP access to trusted management networks and block UDP port 69 from untrusted sources at the perimeter.
  • Disable the TFTP service entirely on hosts that do not require it.
  • Segment or isolate hosts running 3CTftpSvc to limit lateral movement if code execution succeeds.
  • Monitor vendor advisories for updated guidance since the record is old and may lack current patch information.

Detection

  • Inspect TFTP traffic for GET/PUT requests with abnormally long mode fields or oversized packets.
  • Alert on crashes or unexpected restarts of the 3CTftpSvc process.
  • Monitor for unexpected outbound connections or new processes spawned by the TFTP service, which may indicate code execution.
  • Review network logs for TFTP requests originating from untrusted or unexpected source addresses.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2006-6183 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed9.8CVE-2008-4250Microsoft Windows Server service RPC path canonicalization buffer overflowThe Server service in multiple Windows versions fails to properly handle path canonicalization, allowing a crafted RPC request to overflow a buffer a…KEVEPSS 99%analysed8.8CVE-2025-31277Apple WebKit memory corruption via malicious web contentApple WebKit fails to handle memory correctly when processing crafted web content, leading to memory corruption across Safari, iOS, iPadOS, macOS, tv…KEVEPSS 1.6%analysed8.8CVE-2026-3910Google Chrome V8 improper implementation allows sandbox code executionChrome before 146.0.7680.75 contains an inappropriate implementation in the V8 JavaScript engine, classified as code injection and memory buffer over…KEVEPSS 1.0%analysed8.8CVE-2008-0015Microsoft DirectShow Video ActiveX Control Stack Buffer OverflowA stack-based buffer overflow in the CComVariant::ReadFromStream function in the Active Template Library (ATL) is reachable through the MPEG2TuneRequ…KEVEPSS 77%analysed7.8CVE-2026-20700Apple OS memory corruption allows arbitrary code executionA memory corruption flaw caused by improper state management affects iOS, iPadOS, macOS, tvOS, visionOS and watchOS. Apple states it is aware of a re…KEVEPSS 1.3%analysed8.8CVE-2025-14174Google Chrome ANGLE out-of-bounds memory access on MacChrome on macOS before 143.0.7499.110 contains an out-of-bounds memory access in the ANGLE graphics layer, classified as an out-of-bounds write (CWE-…KEVEPSS 22%analysed

Source: NIST National Vulnerability Database (record CVE-2006-6183), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.