Lucene search

K
cisa_kevCISACISA-KEV-CVE-2023-40044
HistoryOct 05, 2023 - 12:00 a.m.

Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability

2023-10-0500:00:00
CISA
www.cisa.gov
26
progress ws_ftp
deserialization
vulnerability
ad hoc transfer
authenticated attacker
remote commands

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.858

Percentile

98.6%

Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.

CVSS3

10

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS

0.858

Percentile

98.6%