CVE-2023-40044
unknown
KEV
CVSS v3
—
CVSS v2
—
VIR risk
1.5
Description
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
CISA KEV
- Vendor
- Progress
- Product
- WS_FTP Server
- Due date
- 2023-10-26
Predictions
Exploit likelihood
99%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: cisa-kev — https://community.progress.com/s/article/WS-FTP-Server-Critical-Vulnerability-September-2023; https://nvd.nist.gov/vuln/detail/CVE-2023-40044
Exploits
References
Verify integrity in audit chain (admin only). AS-IS.