CVE-2023-40044
| CVE Published | 2023-09-27 |
|---|---|
| Related CWE(s) | CWE-502: Deserialization of Untrusted Data |
| Related Vendor(s) | progress |
| Related Product(s) | ws_ftp_server |
| Exploitation Reported (CISA KEV) | 2023-10-05 |
| CVSS 3 Base Score | 8.8 (HIGH) |
| CVSS 3 Attack Complexity | LOW |
| CVSS 3 Attack Vector | NETWORK |
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
Cyber Threat Graph Context
Explore how this CVE relates to the wider threat graph