cbcvebase.
CVE-2010-3187
published 2010-08-30

CVE-2010-3187: Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

PriorityP264critical10CVSS 2.0
AVNACLAuNCCICAC
EXPLOIT
EPSS
20.03%
97.2th percentile
Buffer overflow in ftpd in IBM AIX 5.3 and earlier allows remote attackers to execute arbitrary code via a long NLST command.

Affected

1 ranges
VendorProductVersion rangeFixed in
ibmaix<= 5.3

Detection & IOCsextracted from sources · hover to see the quote

commandNLST ~AAAAAAAAAA... (2000+ A's)
commandNLST ~" . "A" x 5000
path/etc/security/passwd
filenamecore
  • Flag use of the anonymous/guest FTP credential 'ftp' / '[email protected]' as a potential exploit attempt indicator.
  • ·The exploit targets IBM AIX 5.1, 5.2, and 5.3 (and possibly 4.x); the '-s' flag in the advanced exploit switches from NLST to LIST command for AIX 5.3 compatibility.
  • ·The core dump file is described as 'scrambled'; analysts must search for 13-character DES-looking strings within it to extract password hashes.
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.