Vulnerability record · CVE-2017-15222 · published 24 October 2017
CVE-2017-15222: Ayukov NFTPD buffer overflow allows remote code execution
Nftp Project · Nftp
Ayukov NFTPD 2.0 and earlier contains a classic buffer overflow (CWE-120) that remote attackers can trigger to execute arbitrary code. The flaw is network-reachable with no authentication or user interaction, and public exploit code exists, making it a serious risk for any exposed FTP service.
Description
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated remote code execution with public exploit code and very high EPSS probability, though not in KEV.
What it is
Ayukov NFTPD 2.0 and earlier contains a classic buffer overflow (CWE-120) that remote attackers can trigger to execute arbitrary code. The flaw is network-reachable with no authentication or user interaction, and public exploit code exists, making it a serious risk for any exposed FTP service.
Impact
An unauthenticated remote attacker can execute arbitrary code on the FTP server, gaining full control of the host process and potentially the underlying system.
Attack surface
Reachable over the network via the FTP service (AV:N, PR:N, UI:N); no credentials or user interaction are required to trigger the overflow.
Exploitation
Not listed in CISA KEV, but EPSS is 0.603 (99th percentile) and multiple references are tagged Exploit, including Exploit-DB entries, indicating public exploit code is available.
What to do
- Patch or upgrade NFTPD beyond 2.0; if no fixed release exists, migrate to a maintained FTP server.
- Remove internet exposure of NFTPD and restrict access to trusted management networks.
- Enforce authentication and network ACLs so only known clients can reach the FTP port.
- Monitor vendor and Exploit-DB references for updated fixes and apply them promptly.
Detection
- Inspect FTP service logs for malformed or oversized commands preceding crashes or restarts.
- Alert on unexpected process crashes or restarts of the NFTPD service.
- Monitor for post-exploitation behavior such as new listening ports, spawned shells, or outbound connections from the FTP host.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| http://www.securityfocus.com/bid/101602 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43025/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43448/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46070/ | ExploitThird Party AdvisoryVDB Entry |
| http://www.securityfocus.com/bid/101602 | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43025/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/43448/ | ExploitThird Party AdvisoryVDB Entry |
| https://www.exploit-db.com/exploits/46070/ | ExploitThird Party AdvisoryVDB Entry |
Track CVE-2017-15222 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2017-15222), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.