CVE-2011-2523General(debian / debian_linux)

MEDIUMCVSS 9.8 · CRITICAL

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Prioritize remediation for debian debian_linux systems immediately
  • Assume compromise if assets are exposed
  • Track advisory updates for patch or workaround availability

Recommended action window: Immediate (within 24h)

NVD description

vsftpd 2.3.4 downloaded between 20110630 and 20110703 contains a backdoor which opens a shell on port 6200/tcp.

4.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

MEDIUM

Exploitation

ACTIVE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • debian_linux
  • vsftpd

Threat summary

  • Active exploitation appears in 1 classified signals
  • 8 mentions across 6 observed days
  • Momentum state: stable

What's happening

  • Active exploitation reported across 1 signal
  • Technical details provided in 4 signals
  • General: 5 classified signals
  • Disclosure: 1 classified signal
  • Peaked 3d ago at 2 mentions (2026-06-18); latest day: 1
  • 8 total mentions across 6 days

Affected systems

Products
debian_linuxvsftpd

4 versions affected across 2 products

Deep dive

Activity timeline8 mentions / 6d
01122Mentions · 2026-02-19: 1Mentions · 2026-02-20: 1Mentions · 2026-06-18: 2Mentions · 2026-08-17: 2Mentions · 2026-09-18: 1Mentions · 2026-10-06: 1Active Exploitation · 2026-02-20: 1Technical Details · 2026-02-19: 1Technical Details · 2026-06-18: 2Technical Details · 2026-09-18: 102-1902-2006-1808-1709-1810-06
Signal classification3 categories
General
571.4%
Disclosure
114.3%
Active Exploitation
114.3%
Referenced assets1 URL
Classification over time
DateTotalLabels
2026-02-191
Disclosure1
2026-02-201
Active Exploitation1
2026-06-182
General2
2026-08-172
General2
2026-09-181
General1
Full discourse8 posts
  • Hacker News@HackerrsNews

    FTP is still alive — and still getting pwned. From invisible Nmap scans to root RCE via CVE-2011-2523 & CVE-2015-3306, legacy FTP is a silent gateway. Full Metasploit guide: https://hackernews.in/article/metasploit-ftp-exploitation-guide-from-vulnerability-scanning-to-post-exploitation-for-security-professionals #Metasploit #FTP #InfoSec #Pentesting #CyberSecurity https://t.co/UcdblbmXe8

    0001034
    16 followersView on X
  • Tunecci@truktunecci
    General

    4/7 Then came vulnerability identification. My scan identified a known vsFTPd 2.3.4 backdoor associated with: CVE-2011-2523 This was my first practical experience connecting a software version to a known vulnerability. https://t.co/snhztIOgX8

    Post summary

    The text describes a personal experience of identifying a known vsFTPd 2.3.4 backdoor (CVE-2011-2523) via a vulnerability scan, without providing PoC, exploit tools, patch information, or active exploitation details.

    1000037
    1.8K followersView on X
  • Sir Lakewest | Cybersecurity & Cloud Ⓜ️@Sirlakewest1
    General

    1️⃣1️⃣ Analyze Findings Like a Professional Open any vulnerability to view: 📖 Description 📋 Synopsis 🛠️ Solution 📊 CVSS Score 🔍 Plugin Output Example: CVE-2011-2523 CVSS 10.0 vsftpd 2.3.4 Backdoor https://t.co/ciLHGShkhA

    Post summary

    The post provides an example of how the vulnerability interface displays data—listing the CVE ID, CVSS score, affected product, and a backdoor note—without offering exploit details, patches, or active threat information.

    1000046
    527 followersView on X
  • Sir Lakewest | Cybersecurity & Cloud Ⓜ️@Sirlakewest1
    General

    1️⃣1️⃣ Analyze Findings Like a Professional : Open any vulnerability to view: 📖 Description 📋 Synopsis 🛠️ Solution 📊 CVSS Score 🔍 Plugin Output Example: CVE-2011-2523 CVSS 10.0 vsftpd 2.3.4 Backdoor

    Post summary

    The post lists basic technical details for CVE-2011-2523, highlighting its CVSS score and backdoor nature, but provides no information on PoC, exploit code, active exploitation, or specific patch.

    1000047
    527 followersView on X
  • eng. Mishari Al-Khalifa@engmeshari0
    Active Exploitation

    طلع عندي vsftpd 2.3.4 المرتبط بـ CVE-2011-2523. لكن الأهم من الثغرة نفسها… وجود Bind Shell مفتوح بصلاحيات Root.

    Post summary

    The message reports a vsftpd 2.3.4 instance linked to CVE‑2011‑2523 with a root‑privileged bind shell, indicating that the vulnerability is currently being exploited.

    1000027
    3 followersView on X
  • Md Shahnawaz Alam@AlternateAlam
    Disclosure

    Discovered multiple real-world vulnerabilities mapped to CVEs: vsFTPd Backdoor (CVE-2011-2523) → possible root access UnrealIRCd Backdoor RCE Weak TLS encryption & POODLE vuln Slowloris DoS exposure Web app issues like SQLi & CSRF Seeing CVEs live was a big momen #CyberSecurity https://t.co/OezqyjKzYK

    Post summary

    The tweet reports discovery of several real-world CVE vulnerabilities—including backdoors, TLS/POODLE weaknesses, DoS, and web‑app flaws—without mentioning patches, PoCs, or active exploitation.

    1000045
    3 followersView on X
  • ZOWEH@ZOWEHZEE
    General

    One important lesson from my FTP enumeration: Finding a service version isn't the end. I identified vsftpd 2.3.4, then researched the version and found CVE-2011-2523. I also checked the relevant port and found 6200/tcp closed. THE GOAL: VERIFY, DON'T ASSUME. 🔎 https://t.co/MRtZC1WvwP

    Post summary

    The user recounts discovering vsftpd 2.3.4 and its CVE‑2011‑2523, stressing verification, but provides no technical, exploit, patch, or active‑use details.

    0000022
    11 followersView on X
  • ZOWEH@ZOWEHZEE
    General

    Completed my first full FTP enumeration lab 🔎 • Found 21/tcp • Identified vsftpd 2.3.4 • Tested anonymous login • Enumerated FTP access • Researched CVE-2011-2523 • Checked TCP/6200 and found it closed Learning to verify findings, not assume them. https://t.co/9dg3Lp7O3h

    Post summary

    The tweet reports a lab enumeration of an FTP server (vsftpd 2.3.4), notes the presence of CVE‑2011‑2523, and checks a related port, but offers no exploit details, patch info, or evidence of active exploitation.

    0000016
    11 followersView on X
CPE platform detail4 entries

4 of 4 entries

PartVendorProductVersionTarget SWTarget HW
OSdebiandebian_linux10.0--
OSdebiandebian_linux8.0--
OSdebiandebian_linux9.0--
Appvsftpd_projectvsftpd2.3.4--

Explore more