MEDIUM
Multi-Factor Authentication Bypass in Progress WS_FTP Server
Published Nov 12, 2024
6.5
MEDIUMCVSS 3.1
EPSS 0.41%
Description
In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.
Affected products
-
- Version 0StatusaffectedConstraints<8.8.9
- Version 9.0.*StatusunaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | |||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Progress Software Corporation | WS FTP Server | unaffected |
|
No data.
-
- Version 0StatusaffectedConstraints<8.8.9
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Progress Software | WS Ftp Server | n/a |
|
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (2)
- https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2024 vendor-advisory
- https://www.progress.com/ftp-server product
| Link | Providers | Tags |
|---|---|---|
| https://community.progress.com/s/article/WS-FTP-Server-Service-Pack-November-2024 | vendor-advisory | |
| https://www.progress.com/ftp-server | product |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Nov 12, 2024
Updated Nov 12, 2024
Reserved Oct 15, 2024
Link CVE-2024-9999
CISA Vulnrichment
Updated Nov 12, 2024