CVE-2021-46854
CVE-2021-46854 is a high-severity vulnerability in Proftpd with a CVSS 3.x base score of 7.5. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-401.
Key facts
- Severity: High (CVSS 3.x base score 7.5)
- EPSS exploit prediction: 1% (64th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-401
- Affected product: Proftpd
- Published:
- Last modified:
Description
mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
Frequently asked questions
- What is CVE-2021-46854?
- mod_radius in ProFTPD before 1.3.7c allows memory disclosure to RADIUS servers because it copies blocks of 16 characters.
- How severe is CVE-2021-46854?
- CVE-2021-46854 has a CVSS 3.x base score of 7.5, rated high severity. It is exploitable over network with low attack complexity, requires no privileges and no user interaction. Impact on confidentiality is high, integrity none, and availability none.
- Is CVE-2021-46854 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 1% (64th percentile), an estimate of the probability of exploitation in the next 30 days.
- What products are affected by CVE-2021-46854?
- CVE-2021-46854 affects Proftpd. See the affected-products list for the exact vulnerable versions.
- How do I fix CVE-2021-46854?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround. Given its high severity, prioritise patching exposed systems.
- When was CVE-2021-46854 published?
- CVE-2021-46854 was published on 2022-11-23 and last updated on 2026-06-17.
References
- http://www.proftpd.org/docs/RELEASE_NOTES-1.3.7e
- https://bugs.gentoo.org/811495
- https://github.com/proftpd/proftpd/issues/1284
- https://github.com/proftpd/proftpd/pull/1285
- https://security.gentoo.org/glsa/202305-03
Affected products (1)
- cpe:2.3:a:proftpd:proftpd:*:*:*:*:*:*:*:*
More vulnerabilities in Proftpd
- CVE-2015-3306 — Critical (CVSS 10.0): The mod_copy module in ProFTPD 1.3.5 allows remote attackers to read and write to arbitrary files via the site cpfr and…
- CVE-2010-4221 — Critical (CVSS 10.0): Multiple stack-based buffer overflows in the pr_netio_telnet_gets function in netio.c in ProFTPD before 1.3.3c allow…
- CVE-2010-20103 — Critical (CVSS 9.8): A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and…
- CVE-2019-12815 — Critical (CVSS 9.8): An arbitrary file copy vulnerability in mod_copy in ProFTPD up to 1.3.5b allows for remote code execution and…
- CVE-2011-4130 — Critical (CVSS 9.0): Use-after-free vulnerability in the Response API in ProFTPD before 1.3.3g allows remote authenticated users to execute…
- CVE-2026-63090 — High (CVSS 8.8): ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overflow vulnerability in the mod_sftp module that…
Other CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities
- CVE-2026-46289 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: lib/scatterlist: fix length calculations in…
- CVE-2025-39948 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: ice: fix Rx page leak on multi-buffer frames The…
- CVE-2025-21954 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netmem: prevent TX of unreadable skbs Currently…
- CVE-2024-57947 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: netfilter: nf_set_pipapo: fix initial map…
- CVE-2024-56779 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: nfsd: fix nfs4_openowner leak when concurrent…
- CVE-2024-36911 — Critical (CVSS 9.8): In the Linux kernel, the following vulnerability has been resolved: hv_netvsc: Don't free decrypted memory In CoCo…
Browse all CWE-401 (Missing Release of Memory after Effective Lifetime) vulnerabilities →
Threat intelligence
Threat-intel indicators referencing this CVE:
- 106.51.92.114 (ipv4-addr)
- 31.36.163.95 (ipv4-addr)
- 95.87.248.223 (ipv4-addr)
- 89.46.101.122 (ipv4-addr)
- 41.128.181.196 (ipv4-addr)
- 46.20.146.40 (ipv4-addr)
- 104.248.210.24 (ipv4-addr)
- 188.166.231.184 (ipv4-addr)