Medium severity6.2NVD Advisory· Published Mar 22, 2026· Updated Jun 17, 2026
CVE-2019-25587
CVE-2019-25587
Description
BulletProof FTP Server 2019.0.0.50 contains a denial of service vulnerability in the Storage-Path configuration parameter that allows local attackers to crash the application by supplying an excessively long string value. Attackers can enable the Override Storage-Path setting and paste a buffer of 500 bytes or more to trigger an application crash when saving the configuration.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:bpftpserver:bulletproof_ftp_server:2019.0.0.50:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:bpftpserver:bulletproof_ftp_server:2019.0.0.50:*:*:*:*:*:*:*
- (no CPE)range: 2019.0.0.50
- Range: 2019.0.0.50
Patches
Vulnerability mechanics
References
4- www.exploit-db.com/exploits/46876nvdExploitVDB Entry
- www.vulncheck.com/advisories/bulletproof-ftp-server-storage-path-denial-of-servicenvdThird Party Advisory
- bpftpserver.comnvdProduct
- bpftpserver.com/products/bpftpserver/windows/downloadnvdProduct
News mentions
0No linked articles in our index yet.