S4E just found a medium vulnerable javascript library scanner
high·Product Based Network Vulnerabilities·Updated Oct 7, 2025

CVE-2020-35359 Scanner

CVE-2020-35359 Scanner - Denial Of Service vulnerability in Pure-FTPd

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2020-35359
7.5
CVSS

Pure-FTPd 1.0.48 allows remote attackers to prevent legitimate server use by making enough connections to exceed the connection limit.

Attack Vector
-
Privileges Req.
-
User Interaction
-
Affected
n/aby n/a
n/a
Updated Aug 5, 2026View on NVD →
Detail

Pure-FTPd is a free (BSD), secure, production-quality and standard-conformant FTP server. It is actively maintained and is used broadly in web hosting environments due to its focus on security and ease of configuration. By providing a multitude of features, such as compatibility with all Unix platforms and security protocols, Pure-FTPd meets the needs of both small personal sites and large enterprise environments. As it supports most of the FTP extensions, the software allows for efficient file transfers over the network. Pure-FTPd's modular design enables administrators to easily manage users and virtual domains.

The Denial Of Service (DoS) vulnerability in Pure-FTPd version 1.0.48 is a significant concern as it can lead to the service being overwhelmed and rendered unavailable. This type of vulnerability can be exploited by a malicious actor to exhaust the available connections, thus impacting the legitimate users' ability to use the service. The vulnerability arises from the lack of proper connection limits, which allows for unauthorized flooding of connections. Exploiting such a vulnerability affects the availability aspect of security, leading to potential downtimes.

The Pure-FTPd 1.0.48 version is vulnerable due to its insufficient handling of concurrent connections. Technically, the lack of connection limits allows attackers to start numerous connections to the server without proper checks, thereby overwhelming the server resources. This can be done remotely by sending multiple connection requests rapidly, exploiting the connection exhaustion vulnerability. The problem specifically occurs when the FTP server fails to enforce a maximum limit on simultaneous connections per IP address.

If exploited, this Denial Of Service vulnerability can cause the Pure-FTPd service to become unresponsive, resulting in a loss of access to the files hosted via the FTP server. The downtime can affect users' business operations, leading to data transfer disruptions and potentially causing a significant financial and reputational impact on the organization running the FTP server. Repeated exploitation can also degrade the trust and reliability users have in the service, leading to longer-term implications for service providers.

REFERENCES

Solution Advice
  • Implement proper connection limits to prevent resource exhaustion.
  • Update Pure-FTPd to the latest version where the vulnerability is patched.
  • Use firewall rules to limit the number of simultaneous connections per IP address.
  • Consider implementing rate-limiting mechanisms to mitigate the impact of DoS attacks.
  • Monitor server activity for unusual patterns indicative of a DoS attack.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2020-35359 Scanner - Denial Of Service vulnerability in Pure-FTPd S4E