CRITICAL KEV
Unauthenticated arbitrary file read and remote code execution in CrushFTP
Published Apr 22, 2024 ·Due May 1, 2024
10.0
CRITICALCVSS 3.1
EPSS 99.54%
Description
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authentication to gain administrative access, and perform remote code execution on the server.
Affected products
-
Affected
- ≥ 10.0, < 10.7.1
- ≥ 11.0, < 11.1.0
-
Affected
- ≥ 10.0, < 10.7.1
- ≥ 11.0, < 11.1.0
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (2)
References (9)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-32605 Advisory
- https://github.com/airbus-cert/CVE-2024-4040 exploitThird Party Advisory
- https://www.bleepingcomputer.com/news/security/crushftp-warns-users-to-patch-exploited-zero-day-immediately/ media-coveragePress/Media CoverageThird Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2024-4040 government-resourceUS Government Resource
- https://www.crushftp.com/crush10wiki/Wiki.jsp?page=Update vendor-advisoryPatchVendor Advisory
- https://www.crushftp.com/crush11wiki/Wiki.jsp?page=Update vendor-advisoryPatchVendor Advisory
- https://www.rapid7.com/blog/post/2024/04/23/etr-unauthenticated-crushftp-zero-day-enables-complete-server-compromise/ third-party-advisoryThird Party Advisory
- https://www.reddit.com/r/crowdstrike/comments/1c88788/situational_awareness_20240419_crushftp_virtual/ third-party-advisoryExploitIssue Tracking
- https://www.reddit.com/r/cybersecurity/comments/1c850i2/all_versions_of_crush_ftp_are_vulnerable/ relatedIssue TrackingPatch
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner directcyber
Published Apr 22, 2024
Updated Oct 21, 2025
Reserved Apr 22, 2024
Link CVE-2024-4040
CISA Vulnrichment
Updated Feb 4, 2025
Red Hat
No data
ENISA EUVD
Assigner directcyber
Published Apr 22, 2024
Updated Oct 21, 2025
Exploited since Apr 24, 2024
Link EUVD-2024-32605
GitHub
No data