CVE-2023-40044
Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
3Exploited in Wild
YesDecision
Descriptions
In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.
En las versiones del servidor WS_FTP anteriores a la 8.7.4 y 8.8.2, un atacante previamente autenticado podría aprovechar una vulnerabilidad de deserialización de .NET en el módulo Ad Hoc Transfer para ejecutar comandos remotos en el sistema operativo subyacente del servidor WS_FTP.
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2023-08-08 CVE Reserved
- 2023-09-27 CVE Published
- 2023-10-02 First Exploit
- 2023-10-05 Exploited in Wild
- 2023-10-26 KEV Due Date
- 2024-08-02 CVE Updated
- 2024-10-03 EPSS Updated
CWE
- CWE-502: Deserialization of Untrusted Data
CAPEC
- CAPEC-586: Object Injection
References (10)
URL | Tag | Source |
---|---|---|
https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044 | Third Party Advisory | |
https://censys.com/cve-2023-40044 | Third Party Advisory | |
https://www.rapid7.com/blog/post/2023/09/29/etr-critical-vulnerabilities-in-ws_ftp-server | Third Party Advisory | |
https://www.theregister.com/2023/10/02/ws_ftp_update | Third Party Advisory | |
https://attackerkb.com/topics/bn32f9sNax/cve-2023-40044/rapid7-analysis |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023 | 2023-09-27 | |
https://www.progress.com/ws_ftp | 2023-10-13 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Progress Search vendor "Progress" | Ws Ftp Server Search vendor "Progress" for product "Ws Ftp Server" | < 8.7.4 Search vendor "Progress" for product "Ws Ftp Server" and version " < 8.7.4" | - |
Affected
| ||||||
Progress Search vendor "Progress" | Ws Ftp Server Search vendor "Progress" for product "Ws Ftp Server" | >= 8.8 < 8.8.2 Search vendor "Progress" for product "Ws Ftp Server" and version " >= 8.8 < 8.8.2" | - |
Affected
|