Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2011-2523

Severity
9.8CRITICAL
EPSS
94.3%
top 0.06%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedNov 27
Latest updateApr 22

Description

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:HExploitability: 3.9 | Impact: 5.9

Affected Packages2 packages

CVEListV5vsftpd/vsftpd2.3.4 downloaded between 20110630 and 20110703

Also affects: Debian Linux 10.0, 8.0, 9.0

🔴Vulnerability Details

2
GHSA
GHSA-qf3g-hgw2-8r8h: vsftpd 22022-04-22
CVEList
CVE-2011-2523: vsftpd 22019-11-27

💥Exploits & PoCs

3
Exploit-DB
vsftpd 2.3.4 - Backdoor Command Execution2021-04-12
Exploit-DB
vsftpd 2.3.4 - Backdoor Command Execution (Metasploit)2011-07-05
Nuclei
VSFTPD 2.3.4 - Backdoor Command Execution

📋Vendor Advisories

2
Red Hat
vsftpd: backdoor which opens a shell on port 6200/tcp2011-07-04
Debian
CVE-2011-2523: vsftpd - vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which ...2011

💬Community

1
Bugzilla
CVE-2011-2523 vsftpd: backdoor which opens a shell on port 6200/tcp2019-12-02
CVE-2011-2523 (CRITICAL CVSS 9.8) | vsftpd 2.3.4 downloaded between 201 | cvebase.io