CVE-2023-40044: Progress WS_FTP Server
EPSS90.3%No. 457 of 1739 in KEV
CVE year2023listed the same year
Same vendor in KEV9
Same product1
| Field | Value |
|---|---|
| Vendor | Progress |
| Product | WS_FTP Server |
| Name | Progress WS_FTP Server Deserialization of Untrusted Data Vulnerability |
| Added to KEV | 2023-10-05 |
| US federal due date | 2023-10-26 |
| Ransomware use | Known |
| CWE | CWE-502 |
CISA description
Progress WS_FTP Server contains a deserialization of untrusted data vulnerability in the Ad Hoc Transfer module that allows an authenticated attacker to execute remote commands on the underlying operating system.
Data from CISA's Known Exploited Vulnerabilities (KEV) catalog. EPSS is FIRST's estimated probability of exploitation activity in the next 30 days, refreshed weekly. Always follow the vendor's official guidance.
About this page
A Progress WS_FTP Server vulnerability added to CISA's Known Exploited Vulnerabilities catalog on 2023-10-05.