Back

MEDIUM

Multi-Factor Authentication Bypass in Progress WS_FTP Server

Published Nov 12, 2024

Description

In WS_FTP Server versions before 8.8.9 (2022.0.9), an Incorrect Implementation of Authentication Algorithm in the Web Transfer Module allows users to skip the second-factor verification and log in with username and password only.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner ProgressSoftware
Published Nov 12, 2024
Updated Nov 12, 2024
Reserved Oct 15, 2024
CISA Vulnrichment
Updated Nov 12, 2024
NVD
Status Deferred
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a