The potential risks lie with NFS usage in general AFAIK. If you would follow SOP to secure the NFS server, ideally have it on a private net behind the DMZ where the ftpd resides and only allow access from the ftpd's IP I'm sure that would curb risks somehow.
|