CVE-2023-40044

CVE Published 2023-09-27
Related CWE(s) CWE-502: Deserialization of Untrusted Data
Related Vendor(s) progress
Related Product(s) ws_ftp_server
Exploitation Reported (CISA KEV) 2023-10-05
CVSS 3 Base Score 10.0 (CRITICAL)
CVSS 3 Attack Complexity LOW
CVSS 3 Attack Vector NETWORK

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.  

Cyber Threat Graph Context

Explore how this CVE relates to the wider threat graph

Associated CAPEC Patterns

References