SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface.
History

Fri, 16 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 16 Jan 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Smartftp
Smartftp smartftp
Vendors & Products Smartftp
Smartftp smartftp

Thu, 15 Jan 2026 23:45:00 +0000

Type Values Removed Values Added
Description SmartFTP Client 10.0.2909.0 contains multiple denial of service vulnerabilities that allow attackers to crash the application through specific input manipulation. Attackers can trigger crashes by entering malformed paths, using invalid IP addresses, or clearing connection history in the client's interface.
Title SmartFTP Client 10.0.2909.0 - 'Multiple' Denial of Service
Weaknesses CWE-770
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 4.6, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published: 2026-01-15T23:25:41.916Z

Updated: 2026-01-16T21:12:08.424Z

Reserved: 2026-01-14T14:39:44.738Z

Link: CVE-2021-47791

cve-icon Vulnrichment

Updated: 2026-01-16T15:53:04.104Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-01-16T00:16:22.827

Modified: 2026-01-16T22:16:14.780

Link: CVE-2021-47791

cve-icon Redhat

No data.