← Vulnerability feed

Vulnerability record · CVE-2007-1404 · published 10 March 2007

CVE-2007-1404: ProSysInfo TFTPDWIN tftpd.exe long UDP packet denial of service

PProsysinfo · Tftp Server Tftpdwin

tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 mishandles a long UDP packet in a recv_from call, allowing a remote attacker to crash the service. The flaw is a denial of service in a legacy TFTP daemon, and the record notes it may be related to CVE-2006-4948. No affected versions beyond 0.4.2 are stated.

7.3 CVSS 2.0 High EPSS 67% · top 0.7%
7.3CVSS 2.0 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
16 Jun 2026Last modified by NVD

Description

tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 allows remote attackers to cause a denial of service via a long UDP packet that is not properly handled in a recv_from call. NOTE: this issue might be related to CVE-2006-4948.

AV:A/AC:M/Au:N/C:C/I:N/A:C

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

medium priorityThe flaw is a denial of service in an old, narrowly deployed TFTP server, but a public exploit and very high EPSS score raise the practical risk.

What it is

tftpd.exe in ProSysInfo TFTP Server TFTPDWIN 0.4.2 mishandles a long UDP packet in a recv_from call, allowing a remote attacker to crash the service. The flaw is a denial of service in a legacy TFTP daemon, and the record notes it may be related to CVE-2006-4948. No affected versions beyond 0.4.2 are stated.

Impact

An attacker can cause the TFTP service to become unavailable, disrupting file transfers that depend on it. The CVSS vector also claims a confidentiality impact, but the description only supports denial of service.

Attack surface

Reachable over the network via UDP to the TFTP service port; no authentication is required, and no user interaction is indicated. The CVSS vector is adjacent network (AV:A), which is narrower than the description's 'remote attackers'.

Exploitation

Not listed in CISA KEV, but EPSS is high at roughly 0.667 (99th percentile), and a public Exploit-DB entry (3432) exists. No ransomware association is documented.

What to do

  • Upgrade or replace TFTPDWIN 0.4.2 with a maintained TFTP server, since no fixed version is identified in the record.
  • Restrict UDP access to the TFTP port to trusted hosts and segments using firewall or ACL rules.
  • Disable the TFTP service where it is not operationally required.
  • Monitor the vendor advisory (Secunia 24452) for any patch or updated guidance.

Detection

  • Alert on TFTP service crashes, restarts or unexpected process termination on hosts running tftpd.exe.
  • Inspect UDP traffic to the TFTP port for oversized or malformed packets.
  • Baseline normal TFTP client sources and flag requests from unexpected hosts or segments.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2007-1404 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

Source: NIST National Vulnerability Database (record CVE-2007-1404), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.