Vulnerability record · CVE-2007-1404 · published 10 March 2007
CVE-2007-1404: ProSysInfo TFTPDWIN tftpd.exe long UDP packet denial of service
PProsysinfo · Tftp Server Tftpdwin
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 mishandles a long UDP packet in a recv_from call, allowing a remote attacker to crash the service. The flaw is a denial of service in a legacy TFTP daemon, and the record notes it may be related to CVE-2006-4948. No affected versions beyond 0.4.2 are stated.
Description
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.
AV:A/AC:M/Au:N/C:C/I:N/A:C
Automated analysis
medium priorityThe flaw is a denial of service in an old, narrowly deployed TFTP server, but a public exploit and very high EPSS score raise the practical risk.
What it is
tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 mishandles a long UDP packet in a recv_from call, allowing a remote attacker to crash the service. The flaw is a denial of service in a legacy TFTP daemon, and the record notes it may be related to CVE-2006-4948. No affected versions beyond 0.4.2 are stated.
Impact
An attacker can cause the TFTP service to become unavailable, disrupting file transfers that depend on it. The CVSS vector also claims a confidentiality impact, but the description only supports denial of service.
Attack surface
Reachable over the network via UDP to the TFTP service port; no authentication is required, and no user interaction is indicated. The CVSS vector is adjacent network (AV:A), which is narrower than the description's 'remote attackers'.
Exploitation
Not listed in CISA KEV, but EPSS is high at roughly 0.667 (99th percentile), and a public Exploit-DB entry (3432) exists. No ransomware association is documented.
What to do
- Upgrade or replace TFTPDWIN 0.4.2 with a maintained TFTP server, since no fixed version is identified in the record.
- Restrict UDP access to the TFTP port to trusted hosts and segments using firewall or ACL rules.
- Disable the TFTP service where it is not operationally required.
- Monitor the vendor advisory (Secunia 24452) for any patch or updated guidance.
Detection
- Alert on TFTP service crashes, restarts or unexpected process termination on hosts running tftpd.exe.
- Inspect UDP traffic to the TFTP port for oversized or malformed packets.
- Baseline normal TFTP client sources and flag requests from unexpected hosts or segments.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2007-1404 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2007-1404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.