{
  "document": {
    "category": "csaf_vex",
    "csaf_version": "2.0",
    "publisher": {
      "category": "vendor",
      "contact_details": "https://access.redhat.com/security/team/contact/",
      "issuing_authority": "Red Hat Product Security is responsible for vulnerability handling across all Red Hat products and services.",
      "name": "Red Hat Product Security",
      "namespace": "https://www.redhat.com"
    },
    "title": "denial of service due to limited number of connections allowed",
    "tracking": {
      "current_release_date": "2026-07-25T02:25:44+00:00",
      "generator": {
        "date": "2026-07-25T02:25:44+00:00",
        "engine": {
          "name": "CSAF Generator",
          "version": "3.1.0"
        }
      },
      "id": "CVE-2021-30047",
      "initial_release_date": "2023-08-22T13:18:00+00:00",
      "revision_history": [
        {
          "date": "2026-07-25T02:25:44+00:00",
          "number": "1",
          "summary": "Last generated version"
        }
      ],
      "status": "final",
      "version": "1"
    }
  },
  "product_tree": {
    "branches": [
      {
        "category": "vendor",
        "name": "Red Hat",
        "branches": [
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 10.3",
            "product": {
              "name": "Red Hat Enterprise Linux 10.3",
              "product_id": "rhel-10",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:10"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 6-els",
            "product": {
              "name": "Red Hat Enterprise Linux 6-els",
              "product_id": "rhel-6-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:6"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 7-els",
            "product": {
              "name": "Red Hat Enterprise Linux 7-els",
              "product_id": "rhel-7-els.els",
              "product_identification_helper": {
                "cpe": "cpe:/o:redhat:rhel_els:7"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 8.10.z",
            "product": {
              "name": "Red Hat Enterprise Linux 8.10.z",
              "product_id": "rhel-8",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:8"
              }
            }
          },
          {
            "category": "product_name",
            "name": "Red Hat Enterprise Linux 9.9",
            "product": {
              "name": "Red Hat Enterprise Linux 9.9",
              "product_id": "rhel-9",
              "product_identification_helper": {
                "cpe": "cpe:/a:redhat:enterprise_linux:9"
              }
            }
          },
          {
            "category": "product_version",
            "name": "vsftpd",
            "product": {
              "name": "vsftpd",
              "product_id": "vsftpd",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/vsftpd"
              }
            }
          },
          {
            "category": "product_version",
            "name": "vsftpd-debuginfo",
            "product": {
              "name": "vsftpd-debuginfo",
              "product_id": "vsftpd-debuginfo",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/vsftpd-debuginfo"
              }
            }
          },
          {
            "category": "product_version",
            "name": "vsftpd-sysvinit",
            "product": {
              "name": "vsftpd-sysvinit",
              "product_id": "vsftpd-sysvinit",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/vsftpd-sysvinit"
              }
            }
          },
          {
            "category": "product_version",
            "name": "vsftpd",
            "product": {
              "name": "vsftpd",
              "product_id": "vsftpd.src",
              "product_identification_helper": {
                "purl": "pkg:rpm/redhat/vsftpd?arch=src"
              }
            }
          }
        ]
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:vsftpd"
        },
        "product_reference": "vsftpd",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:vsftpd"
        },
        "product_reference": "vsftpd",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd as a component of Red Hat Enterprise Linux 10.3",
          "product_id": "rhel-10:vsftpd"
        },
        "product_reference": "vsftpd",
        "relates_to_product_reference": "rhel-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:vsftpd"
        },
        "product_reference": "vsftpd",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:vsftpd"
        },
        "product_reference": "vsftpd",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd-debuginfo as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:vsftpd-debuginfo"
        },
        "product_reference": "vsftpd-debuginfo",
        "relates_to_product_reference": "rhel-6-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd-debuginfo as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:vsftpd-debuginfo"
        },
        "product_reference": "vsftpd-debuginfo",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd-sysvinit as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:vsftpd-sysvinit"
        },
        "product_reference": "vsftpd-sysvinit",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd.src as a component of Red Hat Enterprise Linux 8.10.z",
          "product_id": "rhel-8:vsftpd.src"
        },
        "product_reference": "vsftpd.src",
        "relates_to_product_reference": "rhel-8"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd.src as a component of Red Hat Enterprise Linux 7-els",
          "product_id": "rhel-7-els.els:vsftpd.src"
        },
        "product_reference": "vsftpd.src",
        "relates_to_product_reference": "rhel-7-els.els"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd.src as a component of Red Hat Enterprise Linux 10.3",
          "product_id": "rhel-10:vsftpd.src"
        },
        "product_reference": "vsftpd.src",
        "relates_to_product_reference": "rhel-10"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd.src as a component of Red Hat Enterprise Linux 9.9",
          "product_id": "rhel-9:vsftpd.src"
        },
        "product_reference": "vsftpd.src",
        "relates_to_product_reference": "rhel-9"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "vsftpd.src as a component of Red Hat Enterprise Linux 6-els",
          "product_id": "rhel-6-els.els:vsftpd.src"
        },
        "product_reference": "vsftpd.src",
        "relates_to_product_reference": "rhel-6-els.els"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2021-30047",
      "cwe": {
        "id": "CWE-400",
        "name": "Uncontrolled Resource Consumption"
      },
      "discovery_date": "2023-08-29T00:00:00+00:00",
      "flags": [
        {
          "label": "inline_mitigations_already_exist",
          "product_ids": [
            "rhel-10:vsftpd",
            "rhel-10:vsftpd.src",
            "rhel-8:vsftpd",
            "rhel-8:vsftpd.src",
            "rhel-9:vsftpd",
            "rhel-9:vsftpd.src"
          ]
        },
        {
          "label": "vulnerable_code_not_present",
          "product_ids": [
            "rhel-6-els.els:vsftpd-debuginfo",
            "rhel-7-els.els:vsftpd-debuginfo"
          ]
        }
      ],
      "notes": [
        {
          "category": "other",
          "text": "vsftpd has a configurable limit to the number of concurrent clients which can be accepted, max_clients. Obviously if this number is exceeded then service is denied to other clients. It is normal practice is to use e.g. firewall rules to limit denial of service attacks. \n\nAs such, Red Hat does not consider this to be a real vulnerability.",
          "title": "Statement"
        },
        {
          "category": "description",
          "text": "VSFTPD is vulnerable to a denial of service, caused by only a limited number of connections allowed, a remote attacker could exploit this vulnerability to cause a denial of service condition.",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "known_affected": [
          "rhel-6-els.els:vsftpd",
          "rhel-6-els.els:vsftpd.src",
          "rhel-7-els.els:vsftpd",
          "rhel-7-els.els:vsftpd-sysvinit",
          "rhel-7-els.els:vsftpd.src"
        ],
        "known_not_affected": [
          "rhel-10:vsftpd",
          "rhel-10:vsftpd.src",
          "rhel-6-els.els:vsftpd-debuginfo",
          "rhel-7-els.els:vsftpd-debuginfo",
          "rhel-8:vsftpd",
          "rhel-8:vsftpd.src",
          "rhel-9:vsftpd",
          "rhel-9:vsftpd.src"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://access.redhat.com/security/cve/CVE-2021-30047"
        },
        {
          "category": "external",
          "summary": "nvd.nist.gov",
          "url": "https://nvd.nist.gov/vuln/detail/CVE-2021-30047"
        },
        {
          "category": "external",
          "summary": "www.cve.org",
          "url": "https://www.cve.org/CVERecord?id=CVE-2021-30047"
        }
      ],
      "remediations": [
        {
          "category": "no_fix_planned",
          "details": "Out of support scope",
          "product_ids": [
            "rhel-6-els.els:vsftpd",
            "rhel-6-els.els:vsftpd.src",
            "rhel-7-els.els:vsftpd",
            "rhel-7-els.els:vsftpd-sysvinit",
            "rhel-7-els.els:vsftpd.src"
          ]
        }
      ],
      "scores": [
        {
          "cvss_v3": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H",
            "baseScore": 7.5,
            "baseSeverity": "HIGH"
          },
          "products": [
            "rhel-10:vsftpd",
            "rhel-10:vsftpd.src",
            "rhel-6-els.els:vsftpd",
            "rhel-6-els.els:vsftpd-debuginfo",
            "rhel-6-els.els:vsftpd.src",
            "rhel-7-els.els:vsftpd",
            "rhel-7-els.els:vsftpd-debuginfo",
            "rhel-7-els.els:vsftpd-sysvinit",
            "rhel-7-els.els:vsftpd.src",
            "rhel-8:vsftpd",
            "rhel-8:vsftpd.src",
            "rhel-9:vsftpd",
            "rhel-9:vsftpd.src"
          ]
        }
      ],
      "title": "denial of service due to limited number of connections allowed"
    }
  ]
}