PatchSiren

PatchSiren cyber security CVE debrief

CVE-2018-25252 Serv-U CVE debrief

FTP Voyager 16.2.0 contains a denial of service vulnerability that allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability can be triggered by creating a malicious site profile containing 500 bytes of repeated characters and pasting it into the IP field, which causes a buffer overflow that crashes the FTP Voyager process. Users of FTP Voyager 16.2.0 should apply patches or mitigations to prevent local denial of service attacks.

Vendor
Serv-U
Product
FTP Voyager
CVSS
MEDIUM 6.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-04
Original CVE updated
2026-07-24
Advisory published
2026-04-04
Advisory updated
2026-07-24

Who should care

Users of FTP Voyager 16.2.0 should apply patches or mitigations to prevent local denial of service attacks. This vulnerability has a CVSS score of 6.9 and a severity of MEDIUM, indicating a medium priority for remediation. Operators, administrators, and security teams responsible for FTP Voyager 16.2.0 deployments should review and implement mitigations to prevent exploitation.

Technical summary

FTP Voyager 16.2.0 has a denial of service vulnerability via site profile IP field. Local attackers can create a malicious site profile containing 500 bytes of repeated characters and paste it into the IP field to trigger a buffer overflow that crashes the FTP Voyager process. The vulnerability has a CVSS score of 6.9 and a severity of MEDIUM. The vulnerability affects the FTP Voyager 16.2.0 application and can be mitigated by applying patches or updates from the vendor.

Defensive priority

Medium priority due to local attack vector and potential for service disruption.

Recommended defensive actions

  • Apply patches or updates from the vendor to address the vulnerability.
  • Implement compensating controls such as limiting access to the site profile IP field.
  • Monitor FTP Voyager logs for suspicious activity.
  • Review and implement additional security controls to prevent similar vulnerabilities.
  • Conduct regular vulnerability assessments and penetration testing to identify potential weaknesses.
  • Develop and implement an incident response plan in case of a security breach.
  • Verify that FTP Voyager 16.2.0 deployments are properly configured and secured.

Evidence notes

The CVE record and NVD details provide evidence of the vulnerability. Vendor advisories and exploit details are also available. The vulnerability affects FTP Voyager 16.2.0 and allows local attackers to crash the application by injecting oversized buffer data into the site profile IP field. Evidence limits suggest that additional verification may be required to confirm affected scope and severity.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-04T14:16:21.367Z and has not been modified since then.