CVE-2023-40044
גבוהה 8.8 מנוצלת בשטח (KEV) בשימוש בכופרה
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 90% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-502
מוצרים מושפעים
progress: ws ftp server
קישורים
- https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-… Vendor Advisory
- https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-… Vendor Advisory
- http://packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-Unauthent… ExploitThird Party AdvisoryVDB Entry
- https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-… ExploitThird Party Advisory
- http://packetstormsecurity.com/files/174917/Progress-Software-WS_FTP-Unauthent… ExploitThird Party AdvisoryVDB Entry
- https://www.assetnote.io/resources/research/rce-in-progress-ws-ftp-ad-hoc-via-… ExploitThird Party Advisory
- https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044 Third Party Advisory
- https://censys.com/cve-2023-40044/ Third Party Advisory
- https://www.progress.com/ws_ftp Product
- https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws… Broken LinkThird Party Advisory