CVE-2021-47865: ProFTPD 1.3.7a - Remote Denial of Service
Published Jan 21, 2026
·Updated
ProFTPD 1.3.7a contains a denial of service vulnerability that allows attackers to overwhelm the server by creating multiple simultaneous FTP connections. Attackers can repeatedly establish connections using threading to exhaust server connection limits and block legitimate user access.
Affected Software
1 affected component
ProFTPD ProFTPD
Event History
Jan 21, 2026
CVE Published
via MITRE·05:27 PM
Data Sourced
via MITRE·05:27 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-47865?
CVE-2021-47865 has a severity rating of medium due to its potential for causing a denial of service.
2
How do I fix CVE-2021-47865?
To fix CVE-2021-47865, upgrade to a patched version of ProFTPD that addresses this denial of service vulnerability.
3
What type of vulnerability is CVE-2021-47865?
CVE-2021-47865 is classified as a remote denial of service vulnerability.
4
Can CVE-2021-47865 be exploited remotely?
Yes, CVE-2021-47865 can be exploited remotely by attackers who create multiple simultaneous FTP connections.
5
What products are affected by CVE-2021-47865?
CVE-2021-47865 affects ProFTPD version 1.3.7a.