Executive brief
FTP Voyager, a file transfer client used for managing remote server connections, is vulnerable to a flaw that can cause the application to crash. A local user can trigger this by entering an excessively long string of characters into the IP address field of a site profile. This results in a denial-of-service condition, preventing the software from being used until it is restarted.
Technical details
A stack-based buffer overflow (CWE-787) exists in FTP Voyager version 16.2.0 and potentially earlier versions. The vulnerability is located in the 'IP' field within the Site Profile configuration menu. A local attacker can trigger the flaw by pasting a malformed string of approximately 500 bytes into this field, leading to an out-of-bounds write that crashes the application process. While this is a denial-of-service vulnerability, the local nature and lack of required privileges make it a medium-severity risk for multi-user environments. The product feature has since been deprecated in newer versions of the Serv-U suite.
Affected products
- SolarWinds FTP Voyager 16.2.0 and earlier
Timeline
- 2018-10-02: disclosed: Initial discovery and vendor notification
- 2018-10-03: other: Proof of concept exploit published on Exploit-DB
- 2026-04-04: advisory: CVE formally published/assigned via VulnCheck