Lucene search

K
cve[email protected]CVE-2023-40044
HistorySep 27, 2023 - 3:18 p.m.

CVE-2023-40044

2023-09-2715:18:57
CWE-502
web.nvd.nist.gov
286
In Wild
36
cve-2023-40044
ws_ftp server
.net deserialization
vulnerability
ad hoc transfer

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.886 High

EPSS

Percentile

98.7%

In WS_FTP Server versions prior to 8.7.4 and 8.8.2, a pre-authenticated attacker could leverage a .NET deserialization vulnerability in the Ad Hoc Transfer module to execute remote commands on the underlying WS_FTP Server operating system.

Affected configurations

NVD
Node
progressws_ftp_serverRange<8.7.4
OR
progressws_ftp_serverRange8.8–8.8.2

CNA Affected

[
  {
    "defaultStatus": "affected",
    "modules": [
      "Ad Hoc Transfer Module"
    ],
    "product": "WS_FTP Server",
    "vendor": "Progress Software Corporation",
    "versions": [
      {
        "lessThan": "8.8.2",
        "status": "affected",
        "version": "8.8.0",
        "versionType": "semver"
      },
      {
        "lessThan": "8.7.4",
        "status": "affected",
        "version": "8.7.0",
        "versionType": "semver"
      }
    ]
  }
]

Social References

More

10 High

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

CHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

8.6 High

AI Score

Confidence

High

0.886 High

EPSS

Percentile

98.7%