// For flags

CVE-2023-40044

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

Severity Score

8.8
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

3
*Multiple Sources

Exploited in Wild

Yes
*KEV

Decision

-
*SSVC
Descriptions

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

En las versiones del servidor WS_FTP anteriores a la 8.7.4 y 8.8.2, un atacante previamente autenticado podría aprovechar una vulnerabilidad de deserialización de .NET en el módulo Ad Hoc Transfer para ejecutar comandos remotos en el sistema operativo subyacente del servidor WS_FTP.

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

*Credits: Shubham Shah - Assetnote, Sean Yeoh - Assetnote
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-08-08 CVE Reserved
  • 2023-09-27 CVE Published
  • 2023-10-02 First Exploit
  • 2023-10-05 Exploited in Wild
  • 2023-10-26 KEV Due Date
  • 2024-08-02 CVE Updated
  • 2024-10-03 EPSS Updated
CWE
  • CWE-502: Deserialization of Untrusted Data
CAPEC
  • CAPEC-586: Object Injection
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Progress
Search vendor "Progress"
Ws Ftp Server
Search vendor "Progress" for product "Ws Ftp Server"
< 8.7.4
Search vendor "Progress" for product "Ws Ftp Server" and version " < 8.7.4"
-
Affected
Progress
Search vendor "Progress"
Ws Ftp Server
Search vendor "Progress" for product "Ws Ftp Server"
>= 8.8 < 8.8.2
Search vendor "Progress" for product "Ws Ftp Server" and version " >= 8.8 < 8.8.2"
-
Affected