CyberRota Analysis
AI-GeneratedThe FTP parser in Suricata versions prior to 8.0.6 is vulnerable to improper handling of RETR or STOR commands sent before PORT or PASV negotiations, leading to a fatal application-layer error that disables further FTP parsing. This can result in the evasion of parser-dependent rules and logging, potentially allowing malicious commands to go undetected. Organizations using Suricata for network security should prioritize upgrading to version 8.0.6 to mitigate this risk.
Public Exploit Signal
A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.
Note: these links are listed for security research and verification purposes only.
Original NVD Description
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to 8.0.6, the FTP parser in src/app-layer-ftp.c treats a RETR or STOR command sent before PORT or PASV negotiation as a fatal application-layer error instead of a recoverable protocol event. The fatal state disables FTP application-layer parsing for the remainder of the TCP flow, so later commands can evade parser-dependent rules and logging; IPS mode instead drops the flow. This issue is fixed in version 8.0.6.
Related CVEs
Other vulnerabilities affecting the same vendor(s)