acFTP Authentication Issue

Risk: High
Local: No
Remote: Yes

CVSS Base Score: 10/10
Impact Subscore: 10/10
Exploitability Subscore: 10/10
Exploit range: Remote
Attack complexity: Low
Authentication: No required
Confidentiality impact: Complete
Integrity impact: Complete
Availability impact: Complete

acFTP is an open-source FTP daemon for Windows platforms ( that offers more functionality than many proprietary servers (including the MS FTP service). The authentication code of acFTP contains a flaw -- specifically, the server treats users as logged in without a valid password. This results in mis-representation of server activity in log files, and possibly privilege elevation. For example: USER private PASS # This leads it to reject my password, but I can not log in with another set of credentials, and my log activity appears as "private" instead of the appropriate "-" or "***".

Vote for this issue:


Thanks for you vote!


Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.

(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2023,


Back to Top