CVE-2023-40044
CVE Published | 2023-09-27 |
---|---|
Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
Related Vendor(s) | progress |
Related Product(s) | ws_ftp_server |
Exploitation Reported (CISA KEV) | 2023-10-05 |
CVSS 3 Base Score | 10.0 (CRITICAL) |
CVSS 3 Attack Complexity | LOW |
CVSS 3 Attack Vector | NETWORK |
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph