Lucene search

K
cveRapid7CVE-2023-2990
HistoryJun 22, 2023 - 8:15 p.m.

CVE-2023-2990

2023-06-2220:15:09
CWE-400
CWE-674
rapid7
web.nvd.nist.gov
23
cve-2023-2990
fortra
globalscape eft
denial of service
vulnerability
nvd

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

30.8%

Fortra Globalscape EFT versions before 8.1.0.16 suffer from a denial of service vulnerability, where a compressed message that decompresses to itself can cause infinite recursion and crash the service

Affected configurations

Nvd
Node
globalscapeeft_serverRange<8.1.0.16
VendorProductVersionCPE
globalscapeeft_server*cpe:2.3:a:globalscape:eft_server:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "platforms": [
      "Windows"
    ],
    "product": "Globalscape EFT",
    "vendor": "Fortra",
    "versions": [
      {
        "lessThan": "8.1.0.16",
        "status": "affected",
        "version": "8.0.0",
        "versionType": "semver"
      }
    ]
  }
]

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

AI Score

7.7

Confidence

High

EPSS

0.001

Percentile

30.8%

Related for CVE-2023-2990