A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
History

Fri, 22 Aug 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Proftpd
Proftpd proftpd
Proftpd Project
Proftpd Project proftpd
Vendors & Products Proftpd
Proftpd proftpd
Proftpd Project
Proftpd Project proftpd

Wed, 20 Aug 2025 15:45:00 +0000

Type Values Removed Values Added
Description A malicious backdoor was embedded in the official ProFTPD 1.3.3c source tarball distributed between November 28 and December 2, 2010. The backdoor implements a hidden FTP command trigger that, when invoked, causes the server to execute arbitrary shell commands with root privileges. This allows remote, unauthenticated attackers to run any OS command on the FTP server host.
Title ProFTPD 1.3.3c Backdoor Command Execution
Weaknesses CWE-912
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2025-08-22T15:44:20.670Z

Reserved: 2025-08-19T16:00:37.400Z

Link: CVE-2010-20103

cve-icon Vulnrichment

Updated: 2025-08-22T15:43:46.558Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-08-20T16:15:34.137

Modified: 2025-08-22T18:09:17.710

Link: CVE-2010-20103

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2025-08-21T12:58:58Z