CVE-2024-4040
קריטית 10.0 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- CrushFTP VFS Sandbox Escape Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
תיאור (מקור, אנגלית)
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
מדדים
- CVSS 3.1
-
10.0 (CRITICAL)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H - EPSS — סבירות ניצול
- 100% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-1336, CWE-94
מוצרים מושפעים
crushftp: crushftp
קישורים
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update PatchVendor Advisory
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update PatchVendor Advisory
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update PatchVendor Advisory
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update PatchVendor Advisory
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_… Issue TrackingPatch
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_… Issue TrackingPatch
- https://github.com/airbus-cert/CVE-2024-4040 ExploitThird Party Advisory
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20… ExploitIssue Tracking
- https://github.com/airbus-cert/CVE-2024-4040 ExploitThird Party Advisory
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20… ExploitIssue Tracking